note 59110 deleted from ref.session by danbrown

From: Date: Sun, 20 Jul 2008 18:26:03 +0000
Subject: note 59110 deleted from ref.session by danbrown
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-142226@lists.php.net to get a copy of this message
Note Submitter: djhoma at gmail dot com ---- As the reference mentions the value of the register_globals variable can cause some problem if you use sessions for verification. If GET variables are registered as global and you check whether the user is already logged in like this: <?php if ($_REQUEST['password'] == "right_password") { $password = true; session_register('password'); } //...later on: if ($password) { //secure content } ?> Notice, that if you guess the name of the verification variable and pass it through the URL (index.php?password=true) and the register_globals is true then a script like this lets you in. I know this is a stupid mistake, but maybe I am not the only one who made it... So after you registered the $password var, you should check the login with session_is_registered() function: <?php if (session_is_registered('password')) { //secure content } ?> This function cannot be fooled by GET or POST variables... Hope it's a useful note!

« previous php.notes (#142226) next »