note 37155 added to security.registerglobals
| From: | cameronNO_SPAM at tripdubdev dot com | Date: | Wed, 05 Nov 2003 07:03:42 +0000 |
| Subject: | note 37155 added to security.registerglobals | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-59923@lists.php.net to get a copy of this message | ||
Here's a useful bit of code I created (can be used for ANY of the different types of variables
GET, POST, COOKIES, etc...)
It's basically a filter that will allow you to pre-filter ALL variables before using them in
your code, reducing risks of security holes at the application level.
Any feedback is greatly appreciated.
<?
$alphabet="\r\n abcdefghijklmnopqrstuvwxyz1234567890<>=/._";
$post=$_POST;
$get=$_GET;
$postcount=count($post) -1;
$getcount=count($get) -1;
$getkeys=array_keys($get);
$postkeys=array_keys($post);
while($getcount>0) {
$key=$getkeys[$getcount];
$variable=$get[$key];
$variable=$variable1=trim(strtolower($variable));
$vnum=0;
while($variable2=$variable1[$vnum]) {
if(!strstr($alphabet,$variable2) || $variable2=="\"") {
$variable=str_replace($variable2,'',$variable);
}
$vnum=$vnum+1;
}
$_GET[$key]=$variable;
$getcount=$getcount-1;
}
while($postcount>0) {
$key=$postkeys[$postcount];
$variable=$post[$key];
$variable=$variable1=trim(strtolower($variable));
$vnum=0;
while($variable2=$variable1[$vnum]) {
if(!strstr($alphabet,$variable2) || $variable2=="\"") {
$variable=str_replace("$variable2","",$variable);
}
$vnum=$vnum+1;
}
$_POST[$key]=$variable;
$postcount=$postcount-1;
}
?>
----
Manual Page -- http://www.php.net/manual/en/security.registerglobals.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+37155
Delete -- http://master.php.net/manage/user-notes.php?action=delete+37155&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+37155&report=yes
Search -- http://master.php.net/manage/user-notes.php