PEAR_Cache_Output documentation

From: Date: Fri, 12 Apr 2002 19:59:36 +0000
Subject: PEAR_Cache_Output documentation
Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-5424@lists.php.net to get a copy of this message
Just wanted to comment on this section in the PEAR_Cache_Output documentation: * // if your script depends on Cookie and HTTP Post data as well * // you should use: * // $cache_handle = array( * // 'file' => $REQUEST_URI, * // 'post' => $HTTP_POST_VARS, * // 'cookie' => $HTTP_COOKIE_VARS * // ); * // But be warned, using all GET or POST Variables as a seed * // can be used for a DOS attack. Calling http://www.example.com/example.php?whatever * // where whatever is a random text might be used to flood your cache. * $cache_handle = $cache->generateID($REQUEST_URI); So $REQUEST_URI is being recommended as a seed value to generate the cache ID, but using POST or GET vars is labeled as DOS vulnerable? But GET vars are part of REQUEST_URI too, and what about: http://www.example.com/example.php/some/random/pathinfo Just as easy to flood the cache via REQUEST_URI... but really is there any way around that, if you're going to try to cache a page whose output depends on any kind of user-supplied values? Carl Meyer

« previous php.pear.dev (#5424) next »