RE: [PHP-DEV] Security Issues
| From: | Zeev Suraski | Date: | Fri, 27 Jul 2001 17:13:13 +0000 |
| Subject: | RE: [PHP-DEV] Security Issues | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-61252@lists.php.net to get a copy of this message | ||
At 04:51 27/07/2001, Marc Boeren wrote:
Changing to register globals=off surely does very little in terms of security for the easily fakeable GPC variables. Maybe not for these variables, but other variables used in your script cannot be faked by passing them as HTTP_POST_VARS. e.g., with register_globals=off if ($HTTP_POST_VARS['user_string'] == 'check_for_security') {*exactly*.// do something, but be aware of security issues }if ($internal_variable == 'whatever') {// do something, knowing that a user could never have set this }The second check is where a lot of scripts are exploitable, I think, if register_globals=on, because programmers do not expect user-input in this variable.