Re: register_globals in php4
| From: | Miguel Cruz | Date: | Thu, 09 May 2002 17:52:40 +0000 |
| Subject: | Re: register_globals in php4 | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-96848@lists.php.net to get a copy of this message | ||
On Fri, 10 May 2002, Patrick Hsieh wrote:
> php4.1 recommends to set register_globals=off in php.ini to make php
> more strict. My question is, if I turn off register_globals, what will
> happen if any malicious user just try to modify the variable values in
> the url? Say,
>
> http://www.domain.com/xxx.php?id=3&sex=female
>
> Does it work if user just change the value in the URL directly and send
> the url directly to web server?
>
> How can we avoid the malicious attack by directly http GET/POST with
> modified parameter values to make possible system error or compromise?
If register_globals is off, then you'll get $_GET['id'] = 3 and
$_GET['sex'] = female. It's then up to you to make sure those are okay.
But at least $id and $sex won't get set until you explicitly set them in
your code.
miguel