Re: PHP 5.1
| From: | Ilia Alshanetsky | Date: | Wed, 02 Feb 2005 03:14:07 +0000 |
| Subject: | Re: PHP 5.1 | ||
| References: | 1 2 3 4 5 6 7 8 9 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-14506@lists.php.net to get a copy of this message | ||
Given that we'd always need to store the raw request data in memory, can we provide some mechanism of accessing it that does not require a function call? If working with integer or floating point based data it is much faster and simpler to just do (int)/(float) cast rather then executing function calls.
Ilia
Rasmus Lerdorf wrote:
Nick Loeve wrote:No, because we don't actually want to lose the raw data. We need to save the raw data internally in PHP and make it available via the filter function. So if a strict default ini filter is enabled you would have something like this: GET /script.php?foo=<xss hack>123 Hello</xss hack> echo $_GET['foo']; Would output: 123 Hello echo filter(GET,'foo',FILTER_RAW); Would output: <xss hack>123 Hello</xss hack> echo filter(GET,'foo',FILTER_NUMBER); Would output: 123 The extra spaces are intentional. Stripped characters are replaced with a single space. So if you had: abc<font size=10>def You would end up with: abc def -RasmusRasmus Lerdorf wrote:Isn't that something you can use mod_security for? I don't know of the availability of that module on a standard host, but on a dedicated server you could install it.I don't actually see it as a per-script thing. Obviously the ini would be per-dir Apache configurable, but I see this as being something set across the board on a dedicated server that defines the security policy of that server.