note 23597 added to security.registerglobals
| From: | php-general at lists dot php dot net | Date: | Tue, 23 Jul 2002 11:53:15 +0000 |
| Subject: | note 23597 added to security.registerglobals | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-33422@lists.php.net to get a copy of this message | ||
Having global variables or indeterminate origin was a pain, but like many things people rely on it.
In a serious production environment, this should be off (if only I had known this could have been
turned off earlier).
However many beginners will have learnt to use this facility, so there should be a means to turn it
on of off on a per site (or per page) basis. After all the server's security model
shouldn't allow php to be running as a user that has serious access to break things anyway.
Any perceived breech should only be a flaw in the php sites coding. The responsiblity for fixing
this is in the author of site, whom should write better php, putting all code inside classes, so
global variables need to be explicity accessed for example. Flaws in C are exactly the same,
don't change the compiler, just fix your code.
--
http://www.php.net/manual/en/security.registerglobals.php
http://master.php.net/manage/user-notes.php?action=edit+23597
http://master.php.net/manage/user-notes.php?action=delete+23597
http://master.php.net/manage/user-notes.php?action=reject+23597