note 40579 added to function.header
| From: | jsvlrtonyahoodotcom at rn2 dot php dot net | Date: | Mon, 08 Mar 2004 16:48:05 +0000 |
| Subject: | note 40579 added to function.header | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-66440@lists.php.net to get a copy of this message | ||
just a security note:
you should always follow a header("Location....."); call with an exit();
reasoning:
if you've got a login check that says, for instance
<?
if(!logged_in())
{
Header("Location: nologin.php")
}
// show secret login-only stuff here
?>
you could construct a browser(/telnet session) that simply ignores HTTP location redirects, and see
the 'secret stuff'
if the code instead read
<?
if(!logged_in())
{
Header("Location: nologin.php")
exit("<a href='nologin.php'>Please click here.</a>");
}
// show secret login-only stuff here
?>
then the attacker would be foiled.
of course, really you should say
<?
if(!logged_in())
{
Header("Location: nologin.php")
exit("<a href='nologin.php'>Please click here.</a>");
} else {
// show secret login-only stuff here
}
?>
just make sure. :P
----
Manual Page -- http://www.php.net/manual/en/function.header.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+40579
Delete -- http://master.php.net/manage/user-notes.php?action=delete+40579&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+40579&report=yes
Search -- http://master.php.net/manage/user-notes.php