note 28770 added to security.registerglobals

From: Date: Thu, 23 Jan 2003 12:05:21 +0000
Subject: note 28770 added to security.registerglobals
Groups: php.notes 
Request: Send a blank email to php-notes+get-42644@lists.php.net to get a copy of this message
If you're using global variables to cope with access levels within your interactive website or application, the safe way is to store the username and password used in the cookies and verify it on every page by having the same auth code included. That way the only hacking that can be done is packet interception to grab passwords (SSL if you're worried about that) or somebody hacking someone else's cookies in IE or something by getting to their computer. (IE settings might have a fix for this although if IE is using SSL to get a cookie one would hope it encrypts the stored data but you never know...) I think reg_global_vars is like any other tool, its only a security risk if you use it unaware of the possibilities. For non-security related variables its a quick and convenient tool, and for security related ones its something to be worked around or avoided. -- http://www.php.net/manual/en/security.registerglobals.php http://master.php.net/manage/user-notes.php?action=edit+28770 http://master.php.net/manage/user-notes.php?action=delete+28770 http://master.php.net/manage/user-notes.php?action=reject+28770

« previous php.notes (#42644) next »