note 47617 deleted from security.globals by danbrown
| From: | danbrown@php.net | Date: | Thu, 15 Jan 2009 16:41:11 +0000 |
| Subject: | note 47617 deleted from security.globals by danbrown | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-149281@lists.php.net to get a copy of this message | ||
Note Submitter: ben at nullcreations dot net
----
Just a note to all the people who think $_SESSION can be poisoned by register_globals - it
can't.
Consider the fact that GET/POST/COOKIE is Processed *before* sessions are. This means that even if
you have register_globals on, and they write to $_SESSION, $_SESSION will just get reset again with
the appropriate values.
Some people take to using extract() as a means to simulate register_globals in scripts where
they're not sure what the server environment will be - this is when you should worry about such
things. The reason is because extract() can concievably occur after GET/POST/COOKIE and SESSION
processing.