Re: extract($_POST)
| From: | ed at home dot homes2see dot com | Date: | Wed, 23 Oct 2002 14:59:14 +0000 |
| Subject: | Re: extract($_POST) | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-121110@lists.php.net to get a copy of this message | ||
The only thing I can see as the most secure way to handle this is to make
sure my scripts are only using $_POST and sitting in a protected directory
accessable only by username and password authentication which is how this
was going to be handled in the first place.
Thanks for all teh help and many suggestions :)
Ed
On Wed, 23 Oct 2002, @ Edwin wrote:
> True. But it seems like even "cookies" can be "stolen".
>
> -----Also from the manual ---------->
> Sessions rely on the session ID, meaning one can 'steal' a session, by
> stealing the session ID. This can be made harder, by using a cookie
> specifically a session cookie, but does not in any way make it impossible
> and still relies on the user closing all browser windows, to expire the
> session cookie. Besides that, even session cookies can be sniffed on a
> network or logged by a proxyserver.
>
> http://www.php.net/manual/en/ref.session.php
>
> So, the bottom line is, nothing is really secure. Programmers/developers
> just need to work harder and make sure that our chocolate cookies are harder
> to steal. I'll just go and finish mine now. ;)
>
> - E
>
> On Wednesday, October 23, 2002 11:23 PM
> "Rick Emery" <remery@emeryloftus.com>
>
> > You are correct. I'd never considered using the URL due to lack of
> security;
> > that is, a user can add URL parameters that hijack the session and make it
> do
> > bad things, or expose data that you (the developer) do not want exposed.
> >
> > ----- Original Message -----
> > From: "@ Edwin" <copperwalls@hotmail.com>
> > To: "Rick Emery" <remery@emeryloftus.com>
> > Cc: <ed@home.homes2see.com>; <php-general@lists.php.net>
> > Sent: Wednesday, October 23, 2002 9:19 AM
> > Subject: Re: [PHP] extract($_POST)
> >
> >
> > Hello,
> >
> > I don't think that's what the manual says:
> >
> > ---------->
> >
> > Passing the Session ID
> >
> > There are two methods to propagate a session id:
> >
> > * Cookies
> > * URL parameter
> >
> > The session module supports both methods. Cookies are optimal, but since
> > they are not reliable (clients are not bound to accept them), we cannot
> rely
> > on them. The second method embeds the session id directly into URLs.
> >
> > http://www.php.net/manual/en/ref.session.php
> >
> > - E
> >
> > On Wednesday, October 23, 2002 10:49 PM
> > "Rick Emery" <remery@emeryloftus.com> wrote:
> >
> > > Ed,
> > >
> > > Elsewhere, you stated that you will not use cookies, because one-third
> > > of your constituency will have cookies turned off. yet, you will use
> > > sessions. Sessions processing depends on cookies being on.
> >
> > ...[snip]...
> >
> >
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php
>