RE: [PHP] extract($_POST)
| From: | HP-Boise,ex1) | Date: | Wed, 23 Oct 2002 19:41:41 +0000 |
| Subject: | RE: [PHP] extract($_POST) | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-121162@lists.php.net to get a copy of this message | ||
Because obscurity is not security :)
You must assume that someone WILL find out you are using $adminAccess and
exploit it, most people I know can't afford to have their machines or data
compromised because their PHP script is hugely insecure.
There is a lot to be said about security, some people try to avoid security
when they can, others like me try to implement as much security as possible
where it makes sense. In the end someone may never attempt to break your
site, but then again they may.
Another thing you need to consider is most likely other people will have at
least read access to your source code, this is true in almost all cases
where more than one person will access the machine. With read access then
can look in your code and see (1.) You are blindly importing variables from
$_POST,$_GET,$_COOKIE,etc or that you have register globals on and (2.) That
you are not initializing your $adminAccess variable before checking the
value; now that same user goes to your website and includes adminAccess =
TRUE in their request and they have access to your website.
When a programmer can make a program more secure without affecting the
end-user it is their responsibility to do so to protect both your client and
you.
In the end super-globals are neat, they help keep user provided variables
separate from your internal variables, they are automatically global and
they add only minimal overhead to your coding. Additionally initializing
variables is easy, and something that should at least be done when you are
using register globals.
Security through obscurity is an illusion, it works for a while, but only
until someone discovers that you are relying on obscurity for security and
then your week (or month) goes down hill from there.
Jason
-----Original Message-----
From: Chris Boget [mailto:chris@wild.net]
Sent: Wednesday, October 23, 2002 1:15 PM
To: 1LT John W. Holmes; Rick Emery; php-general@lists.php.net
Subject: Re: [PHP] extract($_POST)
> Say you have something like this:
> if($_POST['name'] == "John")
> { $admin = TRUE; }
> if($admin)
> { show_sensitive_data(); }
> Now, if you're using extract(), I can send $admin through the post data
and
> you'll extract it into your script. That's where the security flaw lies,
but
> the flaw is in the programming, not PHP.
Ok, this is the problem I have with this example:
How is the malicious user to know that the variable is called $admin if it
does
not show up anywhere in the HTML code and is used only in PHP? If I name
my variable $adminAccess instead, again, how are they to know? They don't
and they can't. So while I understand the basic underlying logic with the
above
argument, I don't understand how setting register_globals to on is any less
secure when you code like that if there is no way the user can know the
variable
name.
I'd be very interested in hearing anyone's opinion on that.
Chris
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php