RE: [PHP] extract($_POST)
| From: | Johnson, Kirk | Date: | Wed, 23 Oct 2002 19:21:28 +0000 |
| Subject: | RE: [PHP] extract($_POST) | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-121158@lists.php.net to get a copy of this message | ||
1. They guess. This isn't as strange as it might seem at first glance: the
first thing programmers are taught is to choose variable names that explain
what the value is. So there is a pretty limited set of frequently occurring
variable names for a flag that says "admin". Those 500 extra posted fields
can be guesses at the name for the "is admin" flag.
2. Somehow, they get a copy of your code.
You can make it harder to guess by choosing bizarre variables names. This is
the "security by obscurity" approach. There are a lot of mixed opinions on
such an approach, however.
It all depends on "how secure" you want to be. The most secure code is code
that you can hand to an attacker and they still can't abuse it. That is the
approach that John is suggesting.
Kirk
> -----Original Message-----
> From: Chris Boget [mailto:chris@wild.net]
> How is the malicious user to know that the variable is called
> $admin if it does
> not show up anywhere in the HTML code and is used only in
> PHP? If I name
> my variable $adminAccess instead, again, how are they to
> know? They don't
> and they can't.