register_globals in php4
| From: | Patrick Hsieh | Date: | Thu, 09 May 2002 17:50:50 +0000 |
| Subject: | register_globals in php4 | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-96847@lists.php.net to get a copy of this message | ||
Hello list,
php4.1 recommends to set register_globals=off in php.ini to make php
more strict. My question is, if I turn off register_globals, what will
happen if any malicious user just try to modify the variable values in
the url? Say,
http://www.domain.com/xxx.php?id=3&sex=female
Does it work if user just change the value in the URL directly and send
the url directly to web server?
How can we avoid the malicious attack by directly http GET/POST with
modified parameter values to make possible system error or compromise?
--
Patrick Hsieh <pahud@pahud.net>
GPG public key http://pahud.net/pubkeys/pahudatpahud.gpg