Path: csiph.com!x330-a1.tempe.blueboxinc.net!usenet.pasdenom.info!aioe.org!eternal-september.org!feeder.eternal-september.org!mx04.eternal-september.org!.POSTED!not-for-mail From: Arno Welzel Newsgroups: comp.lang.php Subject: Re: Magic quotes? Should I still be cautious? Date: Sun, 08 Jan 2012 20:52:18 +0100 Organization: A noiseless patient Spider Lines: 20 Message-ID: <4F09F3F2.50108@arnowelzel.de> References: <4F046877.3080409@arnowelzel.de> <4f05a0b4$0$6924$e4fe514c@news2.news.xs4all.nl> <9mmq09F283U1@mid.uni-berlin.de> Mime-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Injection-Info: mx04.eternal-september.org; posting-host="Psb2+p0U7wkhKleuxO8/EQ"; logging-data="23699"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX19N1NaghgEe9cCYxIAmy7qNArH5gOHCtZI=" User-Agent: Mozilla/5.0 (Windows NT 5.1; rv:9.0) Gecko/20111222 Thunderbird/9.0.1 In-Reply-To: Cancel-Lock: sha1:gIwyckO07U5DBhqDC/jrrnt7lKY= Xref: x330-a1.tempe.blueboxinc.net comp.lang.php:4316 Jerry Stuckle, 2012-01-07 00:12: [...] > I didn't say you didn't need to validate the parameter. But limiting > values to the proper operation makes it harder for hackers to break in. > > It DOES matter where it came from - and data coming in from the wrong > variable can get their IP blocked from the site. There is no use making > it easy for them. So you also check, if a parameter is *not* passed as GET if you expect it as POST? Because otherwise this "security check" would not make any sense. -- Arno Welzel http://arnowelzel.de http://de-rec-fahrrad.de