Re: extract($_POST)
| From: | ed at home dot homes2see dot com | Date: | Wed, 23 Oct 2002 03:08:52 +0000 |
| Subject: | Re: extract($_POST) | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-121022@lists.php.net to get a copy of this message | ||
Ok then, what about this scenario...
Let's for hypothetical puprposes say I have a simple form and that form
that passes 40 variables manually entered in text fields to another script
and there are 100 people submitting that script at the exact same moment
what keeps someone from getting another persons values from the server
using the $_POST['var'] retrieval method?
What would be the most secure way to keep this from happening? This is
what I'm facing at this very moment. I'm now sitting on the verge of a
very large project where there could be potentially 5,000 or more people
using this form at any given moment. Cookies have been eliminated
as a storage option as approximately one third of the end users
would not be allowing cookies onto their system. With this many potential
end users it wouldn't be out of the question that 2 or more people would
be submitting data through the form at the exact same time.
BTW, thanks for all the positive input. This list has been a real help.
Ed
On Wed, 23 Oct 2002, Sascha Cunz wrote:
> If you do it with $_GET and $_POST it's kind of safe. If you include $_SESSION
> in that substitution, you got the same secuirty holes as with
> register_globals=on.
>
> -Sascha
>
> Am Mittwoch, 23. Oktober 2002 01:04 schrieb Rick Emery:
> > Why?
> >
> >
> > ----- Original Message -----
> > From: "Paul Nicholson" <paul@dtnicholson.com>
> > To: "Rick Emery" <remery@emeryloftus.com>; <ed@home.homes2see.com>;
> > <php-general@lists.php.net> Sent: Tuesday, October 22, 2002 5:44 PM
> > Subject: Re: [PHP] extract($_POST)
> >
> >
> > -----BEGIN PGP SIGNED MESSAGE-----
> > Hash: SHA1
> >
> > That is still as dangerous as 'register_global=on' security wise.
> > ~Paul
> >
> > On Tuesday 22 October 2002 02:30 pm, Rick Emery wrote:
> >
> > > Yes, it's safe. To test it yourself, construct a form and name a
> > > variable MYVAR. Display and submit the form so that it passes to a .PHP
> > > script. Do extract($_POST) or extract($HTTP_POST_VARS), and print out
> > > the value of MYVAR
> > > ----- Original Message -----
> > > From: <ed@home.homes2see.com>
> > > To: <php-general@lists.php.net>
> > > Sent: Tuesday, October 22, 2002 1:25 PM
> > > Subject: [PHP] extract($_POST)
> > >
> > >
> > >
> > > Is it safe to assume then that it would be just as safe to use this
> > > command on existing scripts and call this function at the top of every
> > > page you would need to extract post variables from rather as
> > > opposed to rewriting the scripts to use the $_POST['var'] declaration?
> > >
> > > Ed
> > >
> > >
> > >
> > > --
> > > PHP General Mailing List (http://www.php.net/)
> > > To unsubscribe, visit: http://www.php.net/unsub.php
> > >
> > >
> >
> >
> > - --
> > ~Paul Nicholson
> > Design Specialist @ WebPower Design
> > "The web....the way you want it!"
> > paul@webpowerdesign.net
> >
> > "It said uses Windows 98 or better, so I loaded Linux!"
> > Registered Linux User #183202 using Register Linux System # 81891
> > -----BEGIN PGP SIGNATURE-----
> > Version: GnuPG v1.0.6 (GNU/Linux)
> > Comment: For info see http://www.gnupg.org
> >
> > iD8DBQE9tdS8DyXNIUN3+UQRAmjPAJ9SH6VKegJk6KzTksne55564tAq5QCfdl+g
> > eBmDkEXRXQNFlLubFMnesZE=
> > =C2P8
> > -----END PGP SIGNATURE-----
> >
>
> --
> If you want to be a hero, well, just follow me (John Lennon)
>