Re: PHP 5.1

From: Date: Wed, 02 Feb 2005 03:14:07 +0000
Subject: Re: PHP 5.1
References: 1 2 3 4 5 6 7 8 9  Groups: php.internals 
Request: Send a blank email to internals+get-14506@lists.php.net to get a copy of this message
Given that we'd always need to store the raw request data in memory, can we provide some mechanism of accessing it that does not require a function call? If working with integer or floating point based data it is much faster and simpler to just do (int)/(float) cast rather then executing function calls. Ilia Rasmus Lerdorf wrote:
Nick Loeve wrote:
Rasmus Lerdorf wrote:
I don't actually see it as a per-script thing. Obviously the ini would be per-dir Apache configurable, but I see this as being something set across the board on a dedicated server that defines the security policy of that server.
Isn't that something you can use mod_security for? I don't know of the availability of that module on a standard host, but on a dedicated server you could install it.
No, because we don't actually want to lose the raw data. We need to save the raw data internally in PHP and make it available via the filter function. So if a strict default ini filter is enabled you would have something like this: GET /script.php?foo=<xss hack>123 Hello</xss hack> echo $_GET['foo']; Would output: 123 Hello echo filter(GET,'foo',FILTER_RAW); Would output: <xss hack>123 Hello</xss hack> echo filter(GET,'foo',FILTER_NUMBER); Would output: 123 The extra spaces are intentional. Stripped characters are replaced with a single space. So if you had: abc<font size=10>def You would end up with: abc def -Rasmus


« previous php.internals (#14506) next »