note 40579 modified in function.header by victor
| From: | victor@php.net | Date: | Sat, 27 Mar 2004 21:23:32 +0000 |
| Subject: | note 40579 modified in function.header by victor | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-67256@lists.php.net to get a copy of this message | ||
just a security note:
you should always follow a header("Location....."); call with an exit();
--was--
just a security note:
you should always follow a header("Location....."); call with an exit();
reasoning:
if you've got a login check that says, for instance
<?
if(!logged_in())
{
Header("Location: nologin.php")
}
// show secret login-only stuff here
?>
you could construct a browser(/telnet session) that simply ignores HTTP location redirects, and see
the 'secret stuff'
if the code instead read
<?
if(!logged_in())
{
Header("Location: nologin.php")
exit("<a href='nologin.php'>Please click here.</a>");
}
// show secret login-only stuff here
?>
then the attacker would be foiled.
of course, really you should say
<?
if(!logged_in())
{
Header("Location: nologin.php")
exit("<a href='nologin.php'>Please click here.</a>");
} else {
// show secret login-only stuff here
}
?>
just make sure. :P
http://www.php.net/manual/en/function.header.php