register_globals in php4

From: Date: Thu, 09 May 2002 17:50:50 +0000
Subject: register_globals in php4
Groups: php.general 
Request: Send a blank email to php-general+get-96847@lists.php.net to get a copy of this message
Hello list, php4.1 recommends to set register_globals=off in php.ini to make php more strict. My question is, if I turn off register_globals, what will happen if any malicious user just try to modify the variable values in the url? Say, http://www.domain.com/xxx.php?id=3&sex=female Does it work if user just change the value in the URL directly and send the url directly to web server? How can we avoid the malicious attack by directly http GET/POST with modified parameter values to make possible system error or compromise? -- Patrick Hsieh <pahud@pahud.net> GPG public key http://pahud.net/pubkeys/pahudatpahud.gpg

« previous php.general (#96847) next »