Re: solutions to disadvantages when register_globals is off
| From: | Alex Black | Date: | Sun, 21 Jan 2001 20:53:01 +0000 |
| Subject: | Re: solutions to disadvantages when register_globals is off | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-35923@lists.php.net to get a copy of this message | ||
> <?
> include $HTTP_POST_VARS['file'];
> ...
> ?>
>
> really isn't any safer. People won't be able to put file=/etc/passwd
> right in the URL, but they can still trivially fake up a form post and
> inject whatever value for 'file' into the POST data.
>
> It all boils down to verifying any and all user-supplied data.
>
> -Rasmus
totally :)
I toyed with turning off register globals in binarycloud, only to a) have
that pointed out to me, and b) realize that it would be a total hassle.
we're extremely paranoid about user input, and you have to get used to
making your code only accept _exactly_ what it is expecting with regards to
user input.
I've seen:
file.php?message=hello&address=email@domain.com
can you say spam-engine ?
:)
_alex