note 42274 deleted from security.globals by philip

From: Date: Wed, 14 Jul 2004 21:40:11 +0000
Subject: note 42274 deleted from security.globals by philip
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-73239@lists.php.net to get a copy of this message
Note Submitter: Matt AKA Junkie ---- Think of this situation: you're writing an open-source program and there comes the threat of whether or not the end-user will have register_globals off because many free and still many paid hosts have it on by default. Using ini_set() might seem like a good idea, but it doesn't always work. Instead, it's better to just unset all possible global variables (like $PHP_SELF for example). <? $globals = array('_GET', '_POST', '_SERVER', '_FILE', '_COOKIE', '_SESSION'); // add more as desired foreach ($globals as $i => $val) { foreach ($$val as $j => $var) { if (isset($$var)) { unset($$var); } } } // This will unset any potential globals registered ?>

« previous php.notes (#73239) next »