Re: Security Issues

From: Date: Sun, 29 Jul 2001 00:00:05 +0000
Subject: Re: Security Issues
References: 1 2  Groups: php.dev 
Request: Send a blank email to php-dev+get-61340@lists.php.net to get a copy of this message
Björn Schotte wrote:
> 
> * Rasmus Lerdorf wrote:
> > significantly more secure PHP scripts out there.  It will simply cause
> > scripts to break in non-obvious ways and the knee-jerk fix will be to
> > swear at those annoying PHP folks and then turn register_globals on, or
> > they will do something like:
> >
> >   foreach($HTTP_POST_VARS as $key=>$val) $$key = $val;
> >   foreach($HTTP_GET_VARS as $key=>$val) $$key = $val;
> >   foreach($HTTP_COOKIE_VARS as $key=>$val) $$key = $val;
> 
> I fully agree here with Rasmus and I also think this will
> be the workaround for most people -- if one _does_ care
> about security, he even knows what and how to do nowadays.
> I don't think turning register_globals to off will evangelize
> people to develop more secure scripts/applications.

We could at least educate people about extract(). :-P

 - Stig


Thread (133 messages)

« previous php.dev (#61340) next »