Re: Script Security: Best coding practices

From: Date: Thu, 04 Jul 2002 05:41:49 +0000
Subject: Re: Script Security: Best coding practices
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-105362@lists.php.net to get a copy of this message
A suggestion would be to make sure that the variables you're receiving are coming from where you think they're coming from... For instance, $_SESSION['logged_in'] is also (generally) $logged_in but so is $_GET['logged_in'] A smart user could fake it if they wanted to... check the $_SESSION or $_COOKIE or $_POST arrays when it's important, don't just check $logged_in... P.

« previous php.general (#105362) next »