note 38224 added to security.variables
| From: | editor at phpconsulting dot com | Date: | Fri, 12 Dec 2003 21:17:31 +0000 |
| Subject: | note 38224 added to security.variables | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-61873@lists.php.net to get a copy of this message | ||
The following code snippit was written by Mat Caughron, CISSP, in preparation for a final
examination in a course he taught called "Real World PHP" at the University of Nebraska
Omaha.
<?php
foreach ($_POST as $postvarname => $rawpostcontent)
{
array_push($_POST[$postvarname],
strip_tags(substr(trim($rawpostcontent),0,250)));
}
?>
It provides a simple way to apply safe data handling functions (such as strip_tags and string
truncation with substr) to all incoming $_POST variables and addresses three of the OWASP top ten
web programming mistakes mentioned at: http://www.sklar.com/page/article/owasp-top-ten
Note that, as written, it will truncate all incoming variables to 250 characters.
----
Manual Page -- http://www.php.net/manual/en/security.variables.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+38224
Delete -- http://master.php.net/manage/user-notes.php?action=delete+38224&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+38224&report=yes
Search -- http://master.php.net/manage/user-notes.php