Re: extract($_POST)

From: Date: Wed, 23 Oct 2002 14:59:14 +0000
Subject: Re: extract($_POST)
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-121110@lists.php.net to get a copy of this message
The only thing I can see as the most secure way to handle this is to make sure my scripts are only using $_POST and sitting in a protected directory accessable only by username and password authentication which is how this was going to be handled in the first place. Thanks for all teh help and many suggestions :) Ed On Wed, 23 Oct 2002, @ Edwin wrote: > True. But it seems like even "cookies" can be "stolen". > > -----Also from the manual ----------> > Sessions rely on the session ID, meaning one can 'steal' a session, by > stealing the session ID. This can be made harder, by using a cookie > specifically a session cookie, but does not in any way make it impossible > and still relies on the user closing all browser windows, to expire the > session cookie. Besides that, even session cookies can be sniffed on a > network or logged by a proxyserver. > > http://www.php.net/manual/en/ref.session.php > > So, the bottom line is, nothing is really secure. Programmers/developers > just need to work harder and make sure that our chocolate cookies are harder > to steal. I'll just go and finish mine now. ;) > > - E > > On Wednesday, October 23, 2002 11:23 PM > "Rick Emery" <remery@emeryloftus.com> > > > You are correct. I'd never considered using the URL due to lack of > security; > > that is, a user can add URL parameters that hijack the session and make it > do > > bad things, or expose data that you (the developer) do not want exposed. > > > > ----- Original Message ----- > > From: "@ Edwin" <copperwalls@hotmail.com> > > To: "Rick Emery" <remery@emeryloftus.com> > > Cc: <ed@home.homes2see.com>; <php-general@lists.php.net> > > Sent: Wednesday, October 23, 2002 9:19 AM > > Subject: Re: [PHP] extract($_POST) > > > > > > Hello, > > > > I don't think that's what the manual says: > > > > ----------> > > > > Passing the Session ID > > > > There are two methods to propagate a session id: > > > > * Cookies > > * URL parameter > > > > The session module supports both methods. Cookies are optimal, but since > > they are not reliable (clients are not bound to accept them), we cannot > rely > > on them. The second method embeds the session id directly into URLs. > > > > http://www.php.net/manual/en/ref.session.php > > > > - E > > > > On Wednesday, October 23, 2002 10:49 PM > > "Rick Emery" <remery@emeryloftus.com> wrote: > > > > > Ed, > > > > > > Elsewhere, you stated that you will not use cookies, because one-third > > > of your constituency will have cookies turned off. yet, you will use > > > sessions. Sessions processing depends on cookies being on. > > > > ...[snip]... > > > > > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, visit: http://www.php.net/unsub.php >

« previous php.general (#121110) next »