Re: extract($_POST)
| From: | Rasmus Lerdorf | Date: | Wed, 23 Oct 2002 03:15:54 +0000 |
| Subject: | Re: extract($_POST) | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-121025@lists.php.net to get a copy of this message | ||
$_POST and all other such variables are per-request variables. With a
standard Apache 1.3.x setup they are even per-process variables. A single
httpd process only handles one request at a time and these variables are
only there for the duration of a single request. There is simply no way
that this data can bleed into another request.
-Rasmus
On Tue, 22 Oct 2002 ed@home.homes2see.com wrote:
>
> Ok then, what about this scenario...
>
> Let's for hypothetical puprposes say I have a simple form and that form
> that passes 40 variables manually entered in text fields to another script
> and there are 100 people submitting that script at the exact same moment
> what keeps someone from getting another persons values from the server
> using the $_POST['var'] retrieval method?
>
> What would be the most secure way to keep this from happening? This is
> what I'm facing at this very moment. I'm now sitting on the verge of a
> very large project where there could be potentially 5,000 or more people
> using this form at any given moment. Cookies have been eliminated
> as a storage option as approximately one third of the end users
> would not be allowing cookies onto their system. With this many potential
> end users it wouldn't be out of the question that 2 or more people would
> be submitting data through the form at the exact same time.
>
> BTW, thanks for all the positive input. This list has been a real help.
>
> Ed
>
>
> On Wed, 23 Oct 2002, Sascha Cunz wrote:
>
> > If you do it with $_GET and $_POST it's kind of safe. If you include $_SESSION
> > in that substitution, you got the same secuirty holes as with
> > register_globals=on.
> >
> > -Sascha
> >
> > Am Mittwoch, 23. Oktober 2002 01:04 schrieb Rick Emery:
> > > Why?
> > >
> > >
> > > ----- Original Message -----
> > > From: "Paul Nicholson" <paul@dtnicholson.com>
> > > To: "Rick Emery" <remery@emeryloftus.com>;
> > > <ed@home.homes2see.com>;
> > > <php-general@lists.php.net> Sent: Tuesday, October 22, 2002 5:44 PM
> > > Subject: Re: [PHP] extract($_POST)
> > >
> > >
> > > -----BEGIN PGP SIGNED MESSAGE-----
> > > Hash: SHA1
> > >
> > > That is still as dangerous as 'register_global=on' security wise.
> > > ~Paul
> > >
> > > On Tuesday 22 October 2002 02:30 pm, Rick Emery wrote:
> > >
> > > > Yes, it's safe. To test it yourself, construct a form and name a
> > > > variable MYVAR. Display and submit the form so that it passes to a .PHP
> > > > script. Do extract($_POST) or extract($HTTP_POST_VARS), and print out
> > > > the value of MYVAR
> > > > ----- Original Message -----
> > > > From: <ed@home.homes2see.com>
> > > > To: <php-general@lists.php.net>
> > > > Sent: Tuesday, October 22, 2002 1:25 PM
> > > > Subject: [PHP] extract($_POST)
> > > >
> > > >
> > > >
> > > > Is it safe to assume then that it would be just as safe to use this
> > > > command on existing scripts and call this function at the top of every
> > > > page you would need to extract post variables from rather as
> > > > opposed to rewriting the scripts to use the $_POST['var'] declaration?
> > > >
> > > > Ed
> > > >
> > > >
> > > >
> > > > --
> > > > PHP General Mailing List (http://www.php.net/)
> > > > To unsubscribe, visit:
> > > > http://www.php.net/unsub.php
> > > >
> > > >
> > >
> > >
> > > - --
> > > ~Paul Nicholson
> > > Design Specialist @ WebPower Design
> > > "The web....the way you want it!"
> > > paul@webpowerdesign.net
> > >
> > > "It said uses Windows 98 or better, so I loaded Linux!"
> > > Registered Linux User #183202 using Register Linux System # 81891
> > > -----BEGIN PGP SIGNATURE-----
> > > Version: GnuPG v1.0.6 (GNU/Linux)
> > > Comment: For info see http://www.gnupg.org
> > >
> > > iD8DBQE9tdS8DyXNIUN3+UQRAmjPAJ9SH6VKegJk6KzTksne55564tAq5QCfdl+g
> > > eBmDkEXRXQNFlLubFMnesZE=
> > > =C2P8
> > > -----END PGP SIGNATURE-----
> > >
> >
> > --
> > If you want to be a hero, well, just follow me (John Lennon)
> >
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php
>