note 39350 deleted from security.registerglobals by nlopess
| From: | nlopess@php.net | Date: | Sun, 04 Apr 2004 11:09:32 +0000 |
| Subject: | note 39350 deleted from security.registerglobals by nlopess | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-67621@lists.php.net to get a copy of this message | ||
Note Submitter: electronerd@hotmail.com
----
If you are one of the many who think register_globals is the worst thing ever to happen to PHP, but
can't use a .htaccess to just turn the damn thing off, or you need a more fine-grained control
of which scripts use register_globals variables due to using pre-written code, here is some code to
clean your namespace. Put it at global scope, and it will obliterate any variables not in the
safelist array. I have populated my array with the superglobals corresponding to the
register_globals variables, so you can still access the data, but it poses much less of a threat.
<?php
$var_list = get_defined_vars();
$safelist = array('_GET', '_POST', '_COOKIE', '_SERVER',
'_ENV', '_FILES', '_REQUEST');
foreach($var_list as $name => $value)
{
if(array_search($name, $safelist) === FALSE)
{
unset($$name);
}
}
unset($var_list, $name, $value, $safelist);
?>