note 77431 added to security.globals
| From: | MikeWillbanks at osu1 dot php dot net | Date: | Wed, 29 Aug 2007 18:15:07 +0000 |
| Subject: | note 77431 added to security.globals | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-129880@lists.php.net to get a copy of this message | ||
Alans code may get rid of globals but it is slow since it is doing regular expressions on each of
the input items. Then to add on more time the code is being passed through eval.
Besides the slower performance, his code is not checking to see if the variable may have been
changed at any state before this code is being done.
There might be auto_prepended files or include files that might need to run before it. He is also
going through get and post and lastly request which is a little silly seeing as request will contain
the get, post and cookie so he has run get and post twice.
Here is a more effective fix that will take all the keys in request which become variable names and
checks to make sure that the variables match then unsets the element.
<?php
if (ini_get(register_globals)) {
$rg = array_keys($_REQUEST);
foreach($rg as $var)
{
if ($_REQUEST[$v] === $$v)
{
unset($$v);
}
}
}
?>
----
Server IP: 64.71.164.2
Probable Submitter: 209.87.176.4
----
Manual Page -- http://www.php.net/manual/en/security.globals.php
Edit -- https://master.php.net/note/edit/77431
Del: integrated -- https://master.php.net/note/delete/77431/integrated
Del: useless -- https://master.php.net/note/delete/77431/useless
Del: bad code -- https://master.php.net/note/delete/77431/bad+code
Del: spam -- https://master.php.net/note/delete/77431/spam
Del: non-english -- https://master.php.net/note/delete/77431/non-english
Del: in docs -- https://master.php.net/note/delete/77431/in+docs
Del: other reasons-- https://master.php.net/note/delete/77431
Reject -- https://master.php.net/note/reject/77431
Search -- https://master.php.net/manage/user-notes.php