RE: [PHP] extract($_POST)

From: Date: Wed, 23 Oct 2002 19:41:41 +0000
Subject: RE: [PHP] extract($_POST)
Groups: php.general 
Request: Send a blank email to php-general+get-121162@lists.php.net to get a copy of this message
Because obscurity is not security :) You must assume that someone WILL find out you are using $adminAccess and exploit it, most people I know can't afford to have their machines or data compromised because their PHP script is hugely insecure. There is a lot to be said about security, some people try to avoid security when they can, others like me try to implement as much security as possible where it makes sense. In the end someone may never attempt to break your site, but then again they may. Another thing you need to consider is most likely other people will have at least read access to your source code, this is true in almost all cases where more than one person will access the machine. With read access then can look in your code and see (1.) You are blindly importing variables from $_POST,$_GET,$_COOKIE,etc or that you have register globals on and (2.) That you are not initializing your $adminAccess variable before checking the value; now that same user goes to your website and includes adminAccess = TRUE in their request and they have access to your website. When a programmer can make a program more secure without affecting the end-user it is their responsibility to do so to protect both your client and you. In the end super-globals are neat, they help keep user provided variables separate from your internal variables, they are automatically global and they add only minimal overhead to your coding. Additionally initializing variables is easy, and something that should at least be done when you are using register globals. Security through obscurity is an illusion, it works for a while, but only until someone discovers that you are relying on obscurity for security and then your week (or month) goes down hill from there. Jason -----Original Message----- From: Chris Boget [mailto:chris@wild.net] Sent: Wednesday, October 23, 2002 1:15 PM To: 1LT John W. Holmes; Rick Emery; php-general@lists.php.net Subject: Re: [PHP] extract($_POST) > Say you have something like this: > if($_POST['name'] == "John") > { $admin = TRUE; } > if($admin) > { show_sensitive_data(); } > Now, if you're using extract(), I can send $admin through the post data and > you'll extract it into your script. That's where the security flaw lies, but > the flaw is in the programming, not PHP. Ok, this is the problem I have with this example: How is the malicious user to know that the variable is called $admin if it does not show up anywhere in the HTML code and is used only in PHP? If I name my variable $adminAccess instead, again, how are they to know? They don't and they can't. So while I understand the basic underlying logic with the above argument, I don't understand how setting register_globals to on is any less secure when you code like that if there is no way the user can know the variable name. I'd be very interested in hearing anyone's opinion on that. Chris -- PHP General Mailing List (http://www.php.net/) To unsubscribe, visit: http://www.php.net/unsub.php

« previous php.general (#121162) next »