Re: extract($_POST)
| From: | Chris Boget | Date: | Wed, 23 Oct 2002 19:14:32 +0000 |
| Subject: | Re: extract($_POST) | ||
| References: | 1 2 3 4 5 6 7 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-121157@lists.php.net to get a copy of this message | ||
> Say you have something like this:
> if($_POST['name'] == "John")
> { $admin = TRUE; }
> if($admin)
> { show_sensitive_data(); }
> Now, if you're using extract(), I can send $admin through the post data and
> you'll extract it into your script. That's where the security flaw lies, but
> the flaw is in the programming, not PHP.
Ok, this is the problem I have with this example:
How is the malicious user to know that the variable is called $admin if it does
not show up anywhere in the HTML code and is used only in PHP? If I name
my variable $adminAccess instead, again, how are they to know? They don't
and they can't. So while I understand the basic underlying logic with the above
argument, I don't understand how setting register_globals to on is any less
secure when you code like that if there is no way the user can know the variable
name.
I'd be very interested in hearing anyone's opinion on that.
Chris