HTTPS spoofing and $_SERVER

From: Date: Wed, 15 May 2002 11:35:57 +0000
Subject: HTTPS spoofing and $_SERVER
Groups: php.general 
Request: Send a blank email to php-general+get-97695@lists.php.net to get a copy of this message
Hi, I want to know if the user is connected on a secure socket and have two problems: 1. My Apache (Stronghold), variables are not turning up in $_SERVER or $HTTP_SERVER_VARS although they are in $GLOBALS e.g. I have $GLOBALS[SERVER_PORT] but not $_SERVER[SERVER_PORT]. This is with track vars and register globals both on. It seems I have to rely on the $GLOBALS value and be careful with variables_order. 2. As well as $SERVER_PORT, I also get $HTTPS, but only if there it is an HTTPS connect i.e. on a secure connect, $HTTPS == 'on', but on an insecure connect it is not set. This makes it easy to spoof even with variables_order set to ECGPS. I could just use $SERVER_PORT, which is always set and thus not so easily spoofed but then I have to worry if the secure port changes. Any suggestions? George

« previous php.general (#97695) next »