note 39350 added to security.registerglobals
| From: | electronerd at hotmail dot com | Date: | Sun, 25 Jan 2004 17:34:00 +0000 |
| Subject: | note 39350 added to security.registerglobals | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-64165@lists.php.net to get a copy of this message | ||
If you are one of the many who think register_globals is the worst thing ever to happen to PHP, but
can't use a .htaccess to just turn the damn thing off, or you need a more fine-grained control
of which scripts use register_globals variables due to using pre-written code, here is some code to
clean your namespace. Put it at global scope, and it will obliterate any variables not in the
safelist array. I have populated my array with the superglobals corresponding to the
register_globals variables, so you can still access the data, but it poses much less of a threat.
<?php
$var_list = get_defined_vars();
$safelist = array('_GET', '_POST', '_COOKIE', '_SERVER',
'_ENV', '_FILES', '_REQUEST');
foreach($var_list as $name => $value)
{
if(array_search($name, $safelist) === FALSE)
{
unset($$name);
}
}
unset($var_list, $name, $value, $safelist);
?>
----
Manual Page -- http://www.php.net/manual/en/security.registerglobals.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+39350
Delete -- http://master.php.net/manage/user-notes.php?action=delete+39350&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+39350&report=yes
Search -- http://master.php.net/manage/user-notes.php