note 59110 deleted from ref.session by danbrown
| From: | danbrown@php.net | Date: | Sun, 20 Jul 2008 18:26:03 +0000 |
| Subject: | note 59110 deleted from ref.session by danbrown | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-142226@lists.php.net to get a copy of this message | ||
Note Submitter: djhoma at gmail dot com
----
As the reference mentions the value of the register_globals variable can cause some problem if you
use sessions for verification.
If GET variables are registered as global and you check whether the user is already logged in like
this:
<?php
if ($_REQUEST['password'] == "right_password") {
$password = true;
session_register('password');
}
//...later on:
if ($password) {
//secure content
}
?>
Notice, that if you guess the name of the verification variable and pass it through the URL
(index.php?password=true) and the register_globals is true then a script like this lets you in.
I know this is a stupid mistake, but maybe I am not the only one who made it...
So after you registered the $password var, you should check the login with session_is_registered()
function:
<?php
if (session_is_registered('password')) {
//secure content
}
?>
This function cannot be fooled by GET or POST variables...
Hope it's a useful note!