note 10286 deleted from security.filesystem by nlopess
| From: | nlopess@php.net | Date: | Tue, 13 Jan 2004 15:25:31 +0000 |
| Subject: | note 10286 deleted from security.filesystem by nlopess | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-63453@lists.php.net to get a copy of this message | ||
Note Submitter: jqj@darkwing.uoregon.edu
----
One problem with the PHP security model is that a program that might be secure in one environment
isn't in another with only a slightly different configuration. For example, consider the
comments above about HTTP_REMOTE_USER; saying that it's not a problem is correct in some
environments, but not others. For example, if register_globals is set, a cracker can simply pass
HTTP_REMOTE_USER as a GET variable; more generally, the cracker can initialize any variable at all.
Moral: a PHP script should never count on the value of any environment or HTTP_* variable.
A fortiori, a problem with the PHP security model is that it depends so critically on seemingly
small config changes.