RE: [PHP] Why is it dangerous to have register_globals on?

From: Date: Tue, 24 Apr 2001 07:44:08 +0000
Subject: RE: [PHP] Why is it dangerous to have register_globals on?
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-50025@lists.php.net to get a copy of this message
Francois Legare flegare@interchange.ubc.ca > -----Original Message----- > From: Rasmus Lerdorf [mailto:rasmus@php.net] > Sent: April 23, 2001 9:30 PM > To: Plutarck > Cc: php-general@lists.php.net > Subject: Re: [PHP] Why is it dangerous to have register_globals on? > Never never never trust user-supplied data implicitly. Always check > anything that could possibly come from the user. For internal variables, > always initialize them and just generally think things through as you > write your scripts. This is no different in PHP than in any other > scripting language used for web work. > > -Rasmus Hi Rasmus, can you, or anyone else, give more examples to help me understand what you mean by "generally think things through" or give pointer(s) on the web where this topic is being discussed and plenty of examples are given. Actually, any advices, tips and tricks on how to code securely and how to make sure user-supplied data are never implicitly trusted would be more than welcomed. thanks

« previous php.general (#50025) next »