note 22806 deleted from security.registerglobals by philip

From: Date: Mon, 02 Dec 2002 20:14:07 +0000
Subject: note 22806 deleted from security.registerglobals by philip
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-40269@lists.php.net to get a copy of this message
If you choose to follow the new security standard (I did) you might find this useful: define (usually in an included library) this function: function validate_parm($parmname,$type) { switch ($type) { case 'cookie': $basic_security = (!$_GET["$parmname"] && !$_POST["$parmname"] && $_COOKIE["$parmname"] ); break; case 'get' : $basic_security = ($_GET["$parmname"] && !$_POST["$parmname"] && !$_COOKIE["$parmname"] ); break; case 'post' : $basic_security = (!$_GET["$parmname"] && $_POST["$parmname"] && !$_COOKIE["$parmname"] ); break; default : echo "unknown check type: $type for parameter: $parameter"; break; } if ($basic_security) { return $_GET[$parmname]; } else { mail("menja@doma.net", "Possible breakin attempt", $_SERVER['REMOTE_ADDR']); echo "Security violation, admin has been alerted."; exit; } } Then just call it from your scripts like this: $nwidth = validate_parm("nwidth",'get'); Remember, this is very nice as it validates the channel you get your parameters from, but IT DOES NOT CHECK THEIR CONTENT IN ANYWAY. It seems quite right to me, as this is a very abstract control layer. All you have to do is just to check content after validating the channel and "giving birth" to your parameter, as you did before the register_globals_off revolution :)) In this way you basically leave your code intact and just add a few lines at the very beginning of your old script.

« previous php.notes (#40269) next »