note 22806 deleted from security.registerglobals by philip
| From: | philip@php.net | Date: | Mon, 02 Dec 2002 20:14:07 +0000 |
| Subject: | note 22806 deleted from security.registerglobals by philip | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-40269@lists.php.net to get a copy of this message | ||
If you choose to follow the new security standard (I did) you might find this useful:
define (usually in an included library) this function:
function validate_parm($parmname,$type) {
switch ($type) {
case 'cookie':
$basic_security = (!$_GET["$parmname"] && !$_POST["$parmname"]
&& $_COOKIE["$parmname"] );
break;
case 'get' :
$basic_security = ($_GET["$parmname"] && !$_POST["$parmname"]
&& !$_COOKIE["$parmname"] );
break;
case 'post' :
$basic_security = (!$_GET["$parmname"] && $_POST["$parmname"]
&& !$_COOKIE["$parmname"] );
break;
default :
echo "unknown check type: $type for parameter: $parameter";
break;
}
if ($basic_security) {
return $_GET[$parmname];
} else {
mail("menja@doma.net", "Possible breakin attempt",
$_SERVER['REMOTE_ADDR']);
echo "Security violation, admin has been alerted.";
exit;
}
}
Then just call it from your scripts like this:
$nwidth = validate_parm("nwidth",'get');
Remember, this is very nice as it validates the channel you get your parameters from, but IT DOES
NOT CHECK THEIR CONTENT IN ANYWAY. It seems quite right to me, as this is a very abstract control
layer. All you have to do is just to check content after validating the channel and "giving
birth" to your parameter, as you did before the register_globals_off revolution :)) In this way
you basically leave your code intact and just add a few lines at the very beginning of your old
script.