Re: extract($_POST)

From: Date: Wed, 23 Oct 2002 03:15:54 +0000
Subject: Re: extract($_POST)
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-121025@lists.php.net to get a copy of this message
$_POST and all other such variables are per-request variables. With a standard Apache 1.3.x setup they are even per-process variables. A single httpd process only handles one request at a time and these variables are only there for the duration of a single request. There is simply no way that this data can bleed into another request. -Rasmus On Tue, 22 Oct 2002 ed@home.homes2see.com wrote: > > Ok then, what about this scenario... > > Let's for hypothetical puprposes say I have a simple form and that form > that passes 40 variables manually entered in text fields to another script > and there are 100 people submitting that script at the exact same moment > what keeps someone from getting another persons values from the server > using the $_POST['var'] retrieval method? > > What would be the most secure way to keep this from happening? This is > what I'm facing at this very moment. I'm now sitting on the verge of a > very large project where there could be potentially 5,000 or more people > using this form at any given moment. Cookies have been eliminated > as a storage option as approximately one third of the end users > would not be allowing cookies onto their system. With this many potential > end users it wouldn't be out of the question that 2 or more people would > be submitting data through the form at the exact same time. > > BTW, thanks for all the positive input. This list has been a real help. > > Ed > > > On Wed, 23 Oct 2002, Sascha Cunz wrote: > > > If you do it with $_GET and $_POST it's kind of safe. If you include $_SESSION > > in that substitution, you got the same secuirty holes as with > > register_globals=on. > > > > -Sascha > > > > Am Mittwoch, 23. Oktober 2002 01:04 schrieb Rick Emery: > > > Why? > > > > > > > > > ----- Original Message ----- > > > From: "Paul Nicholson" <paul@dtnicholson.com> > > > To: "Rick Emery" <remery@emeryloftus.com>; > > > <ed@home.homes2see.com>; > > > <php-general@lists.php.net> Sent: Tuesday, October 22, 2002 5:44 PM > > > Subject: Re: [PHP] extract($_POST) > > > > > > > > > -----BEGIN PGP SIGNED MESSAGE----- > > > Hash: SHA1 > > > > > > That is still as dangerous as 'register_global=on' security wise. > > > ~Paul > > > > > > On Tuesday 22 October 2002 02:30 pm, Rick Emery wrote: > > > > > > > Yes, it's safe. To test it yourself, construct a form and name a > > > > variable MYVAR. Display and submit the form so that it passes to a .PHP > > > > script. Do extract($_POST) or extract($HTTP_POST_VARS), and print out > > > > the value of MYVAR > > > > ----- Original Message ----- > > > > From: <ed@home.homes2see.com> > > > > To: <php-general@lists.php.net> > > > > Sent: Tuesday, October 22, 2002 1:25 PM > > > > Subject: [PHP] extract($_POST) > > > > > > > > > > > > > > > > Is it safe to assume then that it would be just as safe to use this > > > > command on existing scripts and call this function at the top of every > > > > page you would need to extract post variables from rather as > > > > opposed to rewriting the scripts to use the $_POST['var'] declaration? > > > > > > > > Ed > > > > > > > > > > > > > > > > -- > > > > PHP General Mailing List (http://www.php.net/) > > > > To unsubscribe, visit: > > > > http://www.php.net/unsub.php > > > > > > > > > > > > > > > > > - -- > > > ~Paul Nicholson > > > Design Specialist @ WebPower Design > > > "The web....the way you want it!" > > > paul@webpowerdesign.net > > > > > > "It said uses Windows 98 or better, so I loaded Linux!" > > > Registered Linux User #183202 using Register Linux System # 81891 > > > -----BEGIN PGP SIGNATURE----- > > > Version: GnuPG v1.0.6 (GNU/Linux) > > > Comment: For info see http://www.gnupg.org > > > > > > iD8DBQE9tdS8DyXNIUN3+UQRAmjPAJ9SH6VKegJk6KzTksne55564tAq5QCfdl+g > > > eBmDkEXRXQNFlLubFMnesZE= > > > =C2P8 > > > -----END PGP SIGNATURE----- > > > > > > > -- > > If you want to be a hero, well, just follow me (John Lennon) > > > > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, visit: http://www.php.net/unsub.php >

« previous php.general (#121025) next »