Re: extract($_POST)

From: Date: Wed, 23 Oct 2002 19:45:24 +0000
Subject: Re: extract($_POST)
References: 1 2 3 4 5 6 7 8  Groups: php.general 
Request: Send a blank email to php-general+get-121161@lists.php.net to get a copy of this message
> > Say you have something like this: > > if($_POST['name'] == "John") > > { $admin = TRUE; } > > if($admin) > > { show_sensitive_data(); } > > Now, if you're using extract(), I can send $admin through the post data and > > you'll extract it into your script. That's where the security flaw lies, but > > the flaw is in the programming, not PHP. > > Ok, this is the problem I have with this example: > > How is the malicious user to know that the variable is called $admin if it does > not show up anywhere in the HTML code and is used only in PHP? If I name > my variable $adminAccess instead, again, how are they to know? They don't > and they can't. So while I understand the basic underlying logic with the above > argument, I don't understand how setting register_globals to on is any less > secure when you code like that if there is no way the user can know the variable > name. > > I'd be very interested in hearing anyone's opinion on that. "security by obscurity" as someone pointed out. What's stopping me from running through a dictionary and sending every word to your script, or combinations of words, or random letters? What's to stop me from automating this with my own PHP script and parsing the results back until I find a flaw without having to actually do anything myself?? If the only thing you're protecting is your "special diary" or something, then this will be fine. But I wouldn't protect anything serious with this. ---John Holmes...

« previous php.general (#121161) next »