note 61073 deleted from security.globals by philip
| From: | philip@php.net | Date: | Fri, 28 Apr 2006 16:52:55 +0000 |
| Subject: | note 61073 deleted from security.globals by philip | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-110024@lists.php.net to get a copy of this message | ||
Note Submitter: rumby328 at yahoo dot com
----
Regarding mike at uwmike dot com's snippet, it appears that calling this code causes $GLOBALS
to become recursive within itself with a quick check to get_defined_vars().
A better version of this code without using $GLOBALS with the desired result is:
<?php
if (@ini_get('register_globals'))
{
foreach ($_REQUEST as $key => $value)
{
unset($$key);
}
}
?>
While more effective, this method still leaves non-$_REQUEST vars, such as $_SERVER vars, set. One
could remove these by creating an array of vars to be removed. Consider:
<?php
if (@ini_get('register_globals'))
{
$remove_vars = $_REQUEST + $_SERVER;
foreach ($remove_vars as $key => $value)
{
unset($$key);
}
}
?>