note 25906 added to security.registerglobals
| From: | sorry at rack1 dot php dot net | Date: | Thu, 10 Oct 2002 16:28:45 +0000 |
| Subject: | note 25906 added to security.registerglobals | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-37901@lists.php.net to get a copy of this message | ||
If you are forced to have register_globals=on because of old code, but you are starting a new
project and you want to make sure you don't accidentally use global vars in your new code, you
can run this snippet to unset any global vars that were set.
$arr = array_merge(&$_ENV,&$_GET,&$_POST,&$_COOKIE,&$_SESSION);
while(list($key) = each($arr)) unset(${$key});
I am sure this does not provide any extra security, and is certainly not as effective as setting
register_globals=off, but should keep you from writing more 'bad' code by forcing you to
use super globals.
Anybody have a better way? please post
--
http://www.php.net/manual/en/security.registerglobals.php
http://master.php.net/manage/user-notes.php?action=edit+25906
http://master.php.net/manage/user-notes.php?action=delete+25906
http://master.php.net/manage/user-notes.php?action=reject+25906