Re: Security Issues - a bit of my experience
| From: | Rasmus Lerdorf | Date: | Mon, 30 Jul 2001 04:46:41 +0000 |
| Subject: | Re: Security Issues - a bit of my experience | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-61417@lists.php.net to get a copy of this message | ||
> I was trying to step back a bit and identify some of the patterns in
> the attacks identified in the paper. One extremely popular pattern was
> spoofing variables by overwriting them: GET variables overwriting
> POST, usually, and I suggested that some SAPI stunt be pulled to catch
> that.
That's not the case. The default variable_order is EGPCS which means that
POST variables will always overwrite GET variables of the same name.
-Rasmus