note 23597 added to security.registerglobals

From: Date: Tue, 23 Jul 2002 11:53:15 +0000
Subject: note 23597 added to security.registerglobals
Groups: php.notes 
Request: Send a blank email to php-notes+get-33422@lists.php.net to get a copy of this message
Having global variables or indeterminate origin was a pain, but like many things people rely on it. In a serious production environment, this should be off (if only I had known this could have been turned off earlier). However many beginners will have learnt to use this facility, so there should be a means to turn it on of off on a per site (or per page) basis. After all the server's security model shouldn't allow php to be running as a user that has serious access to break things anyway. Any perceived breech should only be a flaw in the php sites coding. The responsiblity for fixing this is in the author of site, whom should write better php, putting all code inside classes, so global variables need to be explicity accessed for example. Flaws in C are exactly the same, don't change the compiler, just fix your code. -- http://www.php.net/manual/en/security.registerglobals.php http://master.php.net/manage/user-notes.php?action=edit+23597 http://master.php.net/manage/user-notes.php?action=delete+23597 http://master.php.net/manage/user-notes.php?action=reject+23597

« previous php.notes (#33422) next »