Path: csiph.com!x330-a1.tempe.blueboxinc.net!usenet.pasdenom.info!aioe.org!eternal-september.org!feeder.eternal-september.org!mx04.eternal-september.org!.POSTED!not-for-mail From: Arno Welzel Newsgroups: comp.lang.php Subject: Re: Magic quotes? Should I still be cautious? Date: Sun, 08 Jan 2012 20:48:22 +0100 Organization: A noiseless patient Spider Lines: 51 Message-ID: <4F09F306.90700@arnowelzel.de> References: <4F046877.3080409@arnowelzel.de> <4f05a0b4$0$6924$e4fe514c@news2.news.xs4all.nl> <9mmq09F283U1@mid.uni-berlin.de> <9moonbF38cU1@mid.uni-berlin.de> Mime-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Injection-Info: mx04.eternal-september.org; posting-host="Psb2+p0U7wkhKleuxO8/EQ"; logging-data="23699"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18bMePi3zvP6QYM/i6BBcEizr4C/E51KK0=" User-Agent: Mozilla/5.0 (Windows NT 5.1; rv:9.0) Gecko/20111222 Thunderbird/9.0.1 In-Reply-To: <9moonbF38cU1@mid.uni-berlin.de> Cancel-Lock: sha1:5j1usattoMpMiqu17tvLmZSv8HA= Xref: x330-a1.tempe.blueboxinc.net comp.lang.php:4315 M. Strobel, 2012-01-06 18:18: > Am 06.01.2012 14:32, schrieb Jerry Stuckle: >> On 1/6/2012 6:05 AM, Thomas Mlynarczyk wrote: >>> Jerry Stuckle schrieb: >>> >>>> $REQUESTS is quite dangerous. You never know whether it comes >>>> from >>>> $_GET, $_POST or $_COOKIE, for instance. >>> >>> True, you don't know. But does it matter? The only problem I >>> see is that >>> the order of precedence of the three input sources depends on >>> the PHP >>> configuration, but aside from that, the script is given a >>> "foo=bar" and >>> a hacker could always send that via any of GET, POST or COOKIE. >>> So my >>> script should not be dependent on that. I find it rather >>> convenient to >>> be able to send commands/arguments to my script via any of the >>> three >>> methods. >>> >>> Greetings, >>> Thomas >>> >> >> No, it doesn't matter if you aren't concerned about security. >> > > I think programming leaves enough room for everybody to use $_GET > and $_POST to their liking, but > > $_REQUEST is no more dangerous than one of GPC. > > There are some programming mantras you have to keep on saying, > this is not one of it. In fact, PHP has a lot of "historical" security flaws and i agree it is not a good idea to use $_REQUEST instead of $_POST or $_GET. My "hack" to avoid Magic Quotes without changing existing code uses $_REQUEST only, because existing code - which may not be my own code - may rely on it. -- Arno Welzel http://arnowelzel.de http://de-rec-fahrrad.de