Re: Script Security: Best coding practices
| From: | Peter James | Date: | Thu, 04 Jul 2002 05:41:49 +0000 |
| Subject: | Re: Script Security: Best coding practices | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-105362@lists.php.net to get a copy of this message | ||
A suggestion would be to make sure that the variables you're receiving are
coming from where you think they're coming from...
For instance,
$_SESSION['logged_in'] is also (generally) $logged_in
but so is
$_GET['logged_in']
A smart user could fake it if they wanted to... check the $_SESSION or
$_COOKIE or $_POST arrays when it's important, don't just check
$logged_in...
P.