note 40579 modified in function.header by victor

From: Date: Sat, 27 Mar 2004 21:23:32 +0000
Subject: note 40579 modified in function.header by victor
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-67256@lists.php.net to get a copy of this message
just a security note: you should always follow a header("Location....."); call with an exit(); --was-- just a security note: you should always follow a header("Location....."); call with an exit(); reasoning: if you've got a login check that says, for instance <? if(!logged_in()) { Header("Location: nologin.php") } // show secret login-only stuff here ?> you could construct a browser(/telnet session) that simply ignores HTTP location redirects, and see the 'secret stuff' if the code instead read <? if(!logged_in()) { Header("Location: nologin.php") exit("<a href='nologin.php'>Please click here.</a>"); } // show secret login-only stuff here ?> then the attacker would be foiled. of course, really you should say <? if(!logged_in()) { Header("Location: nologin.php") exit("<a href='nologin.php'>Please click here.</a>"); } else { // show secret login-only stuff here } ?> just make sure. :P http://www.php.net/manual/en/function.header.php

« previous php.notes (#67256) next »