note 47617 deleted from security.globals by danbrown

From: Date: Thu, 15 Jan 2009 16:41:11 +0000
Subject: note 47617 deleted from security.globals by danbrown
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-149281@lists.php.net to get a copy of this message
Note Submitter: ben at nullcreations dot net ---- Just a note to all the people who think $_SESSION can be poisoned by register_globals - it can't. Consider the fact that GET/POST/COOKIE is Processed *before* sessions are. This means that even if you have register_globals on, and they write to $_SESSION, $_SESSION will just get reset again with the appropriate values. Some people take to using extract() as a means to simulate register_globals in scripts where they're not sure what the server environment will be - this is when you should worry about such things. The reason is because extract() can concievably occur after GET/POST/COOKIE and SESSION processing.

« previous php.notes (#149281) next »