Re: extract($_POST)

From: Date: Wed, 23 Oct 2002 19:14:32 +0000
Subject: Re: extract($_POST)
References: 1 2 3 4 5 6 7  Groups: php.general 
Request: Send a blank email to php-general+get-121157@lists.php.net to get a copy of this message
> Say you have something like this: > if($_POST['name'] == "John") > { $admin = TRUE; } > if($admin) > { show_sensitive_data(); } > Now, if you're using extract(), I can send $admin through the post data and > you'll extract it into your script. That's where the security flaw lies, but > the flaw is in the programming, not PHP. Ok, this is the problem I have with this example: How is the malicious user to know that the variable is called $admin if it does not show up anywhere in the HTML code and is used only in PHP? If I name my variable $adminAccess instead, again, how are they to know? They don't and they can't. So while I understand the basic underlying logic with the above argument, I don't understand how setting register_globals to on is any less secure when you code like that if there is no way the user can know the variable name. I'd be very interested in hearing anyone's opinion on that. Chris

« previous php.general (#121157) next »