Re: extract($_POST)

From: Date: Wed, 23 Oct 2002 20:09:02 +0000
Subject: Re: extract($_POST)
References: 1 2 3 4 5 6 7 8  Groups: php.general 
Request: Send a blank email to php-general+get-121168@lists.php.net to get a copy of this message
Security through obscurity is a VERY bad idea. Right now, you're saying something like, "no one's going to notice that the vault's not locked... there's no reason to lock it!". Not a good idea. Chris Boget wrote:
Say you have something like this: if($_POST['name'] == "John") { $admin = TRUE; } if($admin) { show_sensitive_data(); } Now, if you're using extract(), I can send $admin through the post data and you'll extract it into your script. That's where the security flaw lies, but the flaw is in the programming, not PHP.
Ok, this is the problem I have with this example: How is the malicious user to know that the variable is called $admin if it does not show up anywhere in the HTML code and is used only in PHP? If I name my variable $adminAccess instead, again, how are they to know? They don't and they can't. So while I understand the basic underlying logic with the above argument, I don't understand how setting register_globals to on is any less secure when you code like that if there is no way the user can know the variable name. I'd be very interested in hearing anyone's opinion on that. Chris
-- The above message is encrypted with double rot13 encoding. Any unauthorized attempt to decrypt it will be prosecuted to the full extent of the law.

« previous php.general (#121168) next »