Re: Security Issues - a bit of my experience

From: Date: Mon, 30 Jul 2001 08:11:34 +0000
Subject: Re: Security Issues - a bit of my experience
References: 1 2 3 4  Groups: php.dev 
Request: Send a blank email to php-dev+get-61499@lists.php.net to get a copy of this message
UNSUBSCRIBE ME PLEASE!!!!!!!!!!!!!! Stephen van Egmond schrieb: > Zeev Suraski (zeev@zend.com) wrote: > > - register_globals=on leads to insecure code, which was demonstrated time > > and time again in the past. > > - Once it's off, we're going to provide methods of accessing variables > > which are just as easy, and quite easier in case you access them from > > functions. Having form variables register as global variables is not the > > 11th commandment, and it's kind of odd to see people treat it as such. > > It is quite the handy feature, and it will be a bummer to see it go. > > > - E_NOTICE is a runtime issue, one which you would have to check under all > > possible paths in your logic. That's why leaving security stuff to runtime > > is always never a good idea. Setting register_globals to off gives you > > development-time security. > > I must point out that if we're referring to existing code bases, > E_NOTICE and register_globals=off require as much work: all code paths > have to be exercised to catch all the old-style idioms. > > I was trying to step back a bit and identify some of the patterns in > the attacks identified in the paper. One extremely popular pattern was > spoofing variables by overwriting them: GET variables overwriting > POST, usually, and I suggested that some SAPI stunt be pulled to catch > that. > > Although this would improve things, it bears noting that: > > - it deprecates a valid (on Apache) idiom which, at least, Rasmus uses > - this only makes it harder to spoof variables, not impossible. > But at least that's something. > > Whatever. The idea hasn't caught on. I recognize it probably wasn't > worthy. > > -Steve > > -- > PHP Development Mailing List <http://www.php.net/> > To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net > For additional commands, e-mail: php-dev-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net

« previous php.dev (#61499) next »