Re: Security Issues

From: Date: Mon, 30 Jul 2001 08:01:32 +0000
Subject: Re: Security Issues
References: 1 2 3  Groups: php.dev 
Request: Send a blank email to php-dev+get-61445@lists.php.net to get a copy of this message
UNSUBSCRIBE ME PLEASE!!!!!!!!!!!!!! "Stig S. Bakken" schrieb: > Björn Schotte wrote: > > > > * Rasmus Lerdorf wrote: > > > significantly more secure PHP scripts out there. It will simply cause > > > scripts to break in non-obvious ways and the knee-jerk fix will be to > > > swear at those annoying PHP folks and then turn register_globals on, or > > > they will do something like: > > > > > > foreach($HTTP_POST_VARS as $key=>$val) $$key = $val; > > > foreach($HTTP_GET_VARS as $key=>$val) $$key = $val; > > > foreach($HTTP_COOKIE_VARS as $key=>$val) $$key = $val; > > > > I fully agree here with Rasmus and I also think this will > > be the workaround for most people -- if one _does_ care > > about security, he even knows what and how to do nowadays. > > I don't think turning register_globals to off will evangelize > > people to develop more secure scripts/applications. > > We could at least educate people about extract(). :-P > > - Stig > > -- > PHP Development Mailing List <http://www.php.net/> > To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net > For additional commands, e-mail: php-dev-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net

« previous php.dev (#61445) next »