PEAR_Cache_Output documentation
| From: | Carl J Meyer | Date: | Fri, 12 Apr 2002 19:59:36 +0000 |
| Subject: | PEAR_Cache_Output documentation | ||
| Groups: | php.pear.dev | ||
| Request: | Send a blank email to pear-dev+get-5424@lists.php.net to get a copy of this message | ||
Just wanted to comment on this section in the PEAR_Cache_Output
documentation:
* // if your script depends on Cookie and HTTP Post data as well
* // you should use:
* // $cache_handle = array(
* // 'file' => $REQUEST_URI,
* // 'post' => $HTTP_POST_VARS,
* // 'cookie' => $HTTP_COOKIE_VARS
* // );
* // But be warned, using all GET or POST Variables as a seed
* // can be used for a DOS attack. Calling
http://www.example.com/example.php?whatever
* // where whatever is a random text might be used to flood your cache.
* $cache_handle = $cache->generateID($REQUEST_URI);
So $REQUEST_URI is being recommended as a seed value to
generate the cache ID, but using POST or GET vars is labeled as DOS
vulnerable? But GET vars are part of REQUEST_URI too, and what about:
http://www.example.com/example.php/some/random/pathinfo
Just as easy to flood the cache via REQUEST_URI... but really is there any
way around that, if you're going to try to cache a page whose
output depends on any kind of user-supplied values?
Carl Meyer