note 28770 added to security.registerglobals
| From: | james at rack1 dot php dot net | Date: | Thu, 23 Jan 2003 12:05:21 +0000 |
| Subject: | note 28770 added to security.registerglobals | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-42644@lists.php.net to get a copy of this message | ||
If you're using global variables to cope with access levels within your interactive website or
application, the safe way is to store the username and password used in the cookies and verify it on
every page by having the same auth code included.
That way the only hacking that can be done is packet interception to grab passwords (SSL if
you're worried about that) or somebody hacking someone else's cookies in IE or something
by getting to their computer. (IE settings might have a fix for this although if IE is using SSL to
get a cookie one would hope it encrypts the stored data but you never know...)
I think reg_global_vars is like any other tool, its only a security risk if you use it unaware of
the possibilities. For non-security related variables its a quick and convenient tool, and for
security related ones its something to be worked around or avoided.
--
http://www.php.net/manual/en/security.registerglobals.php
http://master.php.net/manage/user-notes.php?action=edit+28770
http://master.php.net/manage/user-notes.php?action=delete+28770
http://master.php.net/manage/user-notes.php?action=reject+28770