Re: Security Issues
| From: | Phil Driscoll | Date: | Fri, 27 Jul 2001 11:47:42 +0000 |
| Subject: | Re: Security Issues | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-61197@lists.php.net to get a copy of this message | ||
On Friday 27 July 2001 12:51, Marc Boeren wrote:
> if ($internal_variable == 'whatever') {
> // do something, knowing that a user could never have set this
> }
>
> The second check is where a lot of scripts are exploitable, I think, if
> register_globals=on, because programmers do not expect user-input in this
> variable.
...but will be caught perfectly by E_ALL
--
Phil Driscoll