Re: Re: PHP-4.0.7RC1

From: Date: Fri, 17 Aug 2001 16:33:34 +0000
Subject: Re: Re: PHP-4.0.7RC1
References: 1  Groups: php.dev php.qa 
Request: Send a blank email to php-dev+get-63539@lists.php.net to get a copy of this message
C>> if('foo' == $x){ C>> $secure = true; C>> } C>> ... C>> if($secure){ C>> # do sumthing that needs authentication C>> } C>> C>> This will happily run in E_ALL &~ E_NOTICE whether $x == 'foo' or not. C>> Attacker can then inject $secure in the query string, and it'll apply C>> whether or not $x == 'foo'. This will be caught with error_reporting C>> E_ALL. That's entirely different issue, having nothing to do with notices, but with register_globals and mixing internal and user-supplied variables. The fact that E_NOTICE may in some situation help you to find it is lucky (or, on the second thought, unlucky - it may as well not happen, and you are toast with all your belief in notices) coincidence, nothing more. C>> Yes, average PHP code is full of security or other holes. That's overbroad statement which is just wrong. I can show you a lot of scripts generating a real lot of notices, but having no security hole. Also, note that fixing notice in the above code in the obvious way - changing simple if() to isset and stuff - will shut up your precious notice mechanism, while leaving the hole wide open. Is that what you want? -- Stanislav Malyshev, Zend Products Engineer stas@zend.com http://www.zend.com/ +972-3-6139665 ext.115

« previous php.dev (#63539) next »