Re: Security Issues
| From: | Ramsi Sras | Date: | Mon, 30 Jul 2001 08:01:32 +0000 |
| Subject: | Re: Security Issues | ||
| References: | 1 2 3 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-61445@lists.php.net to get a copy of this message | ||
UNSUBSCRIBE ME PLEASE!!!!!!!!!!!!!!
"Stig S. Bakken" schrieb:
> Björn Schotte wrote:
> >
> > * Rasmus Lerdorf wrote:
> > > significantly more secure PHP scripts out there. It will simply cause
> > > scripts to break in non-obvious ways and the knee-jerk fix will be to
> > > swear at those annoying PHP folks and then turn register_globals on, or
> > > they will do something like:
> > >
> > > foreach($HTTP_POST_VARS as $key=>$val) $$key = $val;
> > > foreach($HTTP_GET_VARS as $key=>$val) $$key = $val;
> > > foreach($HTTP_COOKIE_VARS as $key=>$val) $$key = $val;
> >
> > I fully agree here with Rasmus and I also think this will
> > be the workaround for most people -- if one _does_ care
> > about security, he even knows what and how to do nowadays.
> > I don't think turning register_globals to off will evangelize
> > people to develop more secure scripts/applications.
>
> We could at least educate people about extract(). :-P
>
> - Stig
>
> --
> PHP Development Mailing List <http://www.php.net/>
> To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net
> For additional commands, e-mail: php-dev-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net