note 42274 deleted from security.globals by philip
| From: | philip@php.net | Date: | Wed, 14 Jul 2004 21:40:11 +0000 |
| Subject: | note 42274 deleted from security.globals by philip | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-73239@lists.php.net to get a copy of this message | ||
Note Submitter: Matt AKA Junkie
----
Think of this situation: you're writing an open-source program and there comes the threat of
whether or not the end-user will have register_globals off because many free and still many paid
hosts have it on by default. Using ini_set() might seem like a good idea, but it doesn't always
work. Instead, it's better to just unset all possible global variables (like $PHP_SELF for
example).
<?
$globals = array('_GET', '_POST', '_SERVER', '_FILE',
'_COOKIE', '_SESSION');
// add more as desired
foreach ($globals as $i => $val)
{
foreach ($$val as $j => $var)
{
if (isset($$var)) { unset($$var); }
}
}
// This will unset any potential globals registered
?>