Re: extract($_POST)

From: Date: Wed, 23 Oct 2002 03:08:52 +0000
Subject: Re: extract($_POST)
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-121022@lists.php.net to get a copy of this message
Ok then, what about this scenario... Let's for hypothetical puprposes say I have a simple form and that form that passes 40 variables manually entered in text fields to another script and there are 100 people submitting that script at the exact same moment what keeps someone from getting another persons values from the server using the $_POST['var'] retrieval method? What would be the most secure way to keep this from happening? This is what I'm facing at this very moment. I'm now sitting on the verge of a very large project where there could be potentially 5,000 or more people using this form at any given moment. Cookies have been eliminated as a storage option as approximately one third of the end users would not be allowing cookies onto their system. With this many potential end users it wouldn't be out of the question that 2 or more people would be submitting data through the form at the exact same time. BTW, thanks for all the positive input. This list has been a real help. Ed On Wed, 23 Oct 2002, Sascha Cunz wrote: > If you do it with $_GET and $_POST it's kind of safe. If you include $_SESSION > in that substitution, you got the same secuirty holes as with > register_globals=on. > > -Sascha > > Am Mittwoch, 23. Oktober 2002 01:04 schrieb Rick Emery: > > Why? > > > > > > ----- Original Message ----- > > From: "Paul Nicholson" <paul@dtnicholson.com> > > To: "Rick Emery" <remery@emeryloftus.com>; <ed@home.homes2see.com>; > > <php-general@lists.php.net> Sent: Tuesday, October 22, 2002 5:44 PM > > Subject: Re: [PHP] extract($_POST) > > > > > > -----BEGIN PGP SIGNED MESSAGE----- > > Hash: SHA1 > > > > That is still as dangerous as 'register_global=on' security wise. > > ~Paul > > > > On Tuesday 22 October 2002 02:30 pm, Rick Emery wrote: > > > > > Yes, it's safe. To test it yourself, construct a form and name a > > > variable MYVAR. Display and submit the form so that it passes to a .PHP > > > script. Do extract($_POST) or extract($HTTP_POST_VARS), and print out > > > the value of MYVAR > > > ----- Original Message ----- > > > From: <ed@home.homes2see.com> > > > To: <php-general@lists.php.net> > > > Sent: Tuesday, October 22, 2002 1:25 PM > > > Subject: [PHP] extract($_POST) > > > > > > > > > > > > Is it safe to assume then that it would be just as safe to use this > > > command on existing scripts and call this function at the top of every > > > page you would need to extract post variables from rather as > > > opposed to rewriting the scripts to use the $_POST['var'] declaration? > > > > > > Ed > > > > > > > > > > > > -- > > > PHP General Mailing List (http://www.php.net/) > > > To unsubscribe, visit: http://www.php.net/unsub.php > > > > > > > > > > > > - -- > > ~Paul Nicholson > > Design Specialist @ WebPower Design > > "The web....the way you want it!" > > paul@webpowerdesign.net > > > > "It said uses Windows 98 or better, so I loaded Linux!" > > Registered Linux User #183202 using Register Linux System # 81891 > > -----BEGIN PGP SIGNATURE----- > > Version: GnuPG v1.0.6 (GNU/Linux) > > Comment: For info see http://www.gnupg.org > > > > iD8DBQE9tdS8DyXNIUN3+UQRAmjPAJ9SH6VKegJk6KzTksne55564tAq5QCfdl+g > > eBmDkEXRXQNFlLubFMnesZE= > > =C2P8 > > -----END PGP SIGNATURE----- > > > > -- > If you want to be a hero, well, just follow me (John Lennon) >

« previous php.general (#121022) next »