I believe that the "scare" about HTTP_POST_VARS is that so many beginners
see POST vars as unconquerably tricky to spoof compared to GET, and use POST
vars as a high-level security measure. In reality, POST vars only raise the
bar a little -- Joe Sixpack and Betsy Buick can play with GET vars to see
what happens, while POST vars requires that you be a Script-Kiddie. Not
exactly a "big" step up in security classification.
that´s the truth, all GPC cannot be trusted
Looping through HTTP_POST_VARS itself is not dangerous -- Assuming the data
you get that way is safe is dangerous. If you are filtering your POST vars,
and are aware that *ANY* variable/value combination can be inserted, you
should be okay. Specifically, depending on the security level you require,
you should probably:
1a. Explicitly code for the variables you expect to see, and
1b. Unset everything else, and possibly halt execution on unexpected inputs.
2. Check the possible values/ranges for the values of 1a. variables and halt
execution for any unexpected inputs.
3. Log anything suspicious about 1b or 2 along with any info you consider
useful to trace back to origins.
hmm, I´d call it very much easier to perform a little referrer_check against TrustedPages (TM) and even
then your 1-3 should be done in addition
2c
andré