Re: solutions to disadvantages when register_globals is off

From: Date: Sun, 21 Jan 2001 20:53:01 +0000
Subject: Re: solutions to disadvantages when register_globals is off
References: 1 2  Groups: php.general 
Request: Send a blank email to php-general+get-35923@lists.php.net to get a copy of this message
> <? > include $HTTP_POST_VARS['file']; > ... > ?> > > really isn't any safer. People won't be able to put file=/etc/passwd > right in the URL, but they can still trivially fake up a form post and > inject whatever value for 'file' into the POST data. > > It all boils down to verifying any and all user-supplied data. > > -Rasmus totally :) I toyed with turning off register globals in binarycloud, only to a) have that pointed out to me, and b) realize that it would be a total hassle. we're extremely paranoid about user input, and you have to get used to making your code only accept _exactly_ what it is expecting with regards to user input. I've seen: file.php?message=hello&address=email@domain.com can you say spam-engine ? :) _alex

« previous php.general (#35923) next »