note 15310 rejected and deleted from function.session-start by jmcastagnetto

From: Date: Wed, 05 Sep 2001 19:23:33 +0000
Subject: note 15310 rejected and deleted from function.session-start by jmcastagnetto
Groups: php.notes 
Request: Send a blank email to php-notes+get-17676@lists.php.net to get a copy of this message
while reading alot about security here I'm noticed a couple of bugs on sites with getting into the files without actually loging in at all. For example. I have read alot about never using the variables instead use $HTTP_SESSION_VARS[example]. While doing this work with say this example. www.test.com/search.php?num=1>-- the user is unable to log in to the site and is redirected. But when trying it this way www.test.com/search?num=1 its then unlocked and lets me in and I'm free to do as I please. Anybody have an explanation for that?

« previous php.notes (#17676) next »