Re: How to open random Flash page with hyperlink?
| From: | Curt Zirzow | Date: | Mon, 25 Aug 2003 15:03:40 +0000 |
| Subject: | Re: How to open random Flash page with hyperlink? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-160667@lists.php.net to get a copy of this message | ||
* Thus wrote Cody Phanekham (Cody.Phanekham@salmat.com.au):
> Murugesan,
>
> main.php:
> <?
> session_name("mysessionname");
> session_start();
> if (!$s_authed) // check access
> {
> // user hasnt been authorised, therefore redirect to login page
This is exactly why register globals is turned off by default now.
This is a major security hole, I can simply put in the url:
http://host/main.php?s_authed=1
And I would be considered authenticated, throughout the site.
Please turn register_globals off and use the $_SESSION variable to
access your session vars.
Curt
--
"I used to think I was indecisive, but now I'm not so sure."