Re: Writing Secure PHP Scripts

From: Date: Wed, 06 Sep 2000 00:19:33 +0000
Subject: Re: Writing Secure PHP Scripts
References: 1 2  Groups: php.qa 
Request: Send a blank email to php-qa+get-1230@lists.php.net to get a copy of this message
I believe that the "scare" about HTTP_POST_VARS is that so many beginners see POST vars as unconquerably tricky to spoof compared to GET, and use POST vars as a high-level security measure. In reality, POST vars only raise the bar a little -- Joe Sixpack and Betsy Buick can play with GET vars to see what happens, while POST vars requires that you be a Script-Kiddie. Not exactly a "big" step up in security classification.
that´s the truth, all GPC cannot be trusted
Looping through HTTP_POST_VARS itself is not dangerous -- Assuming the data you get that way is safe is dangerous. If you are filtering your POST vars, and are aware that *ANY* variable/value combination can be inserted, you should be okay. Specifically, depending on the security level you require, you should probably: 1a. Explicitly code for the variables you expect to see, and 1b. Unset everything else, and possibly halt execution on unexpected inputs. 2. Check the possible values/ranges for the values of 1a. variables and halt execution for any unexpected inputs. 3. Log anything suspicious about 1b or 2 along with any info you consider useful to trace back to origins.
hmm, I´d call it very much easier to perform a little referrer_check against TrustedPages (TM) and even then your 1-3 should be done in addition 2c andré

« previous php.qa (#1230) next »