Path: csiph.com!x330-a1.tempe.blueboxinc.net!usenet.pasdenom.info!news.albasani.net!fu-berlin.de!uni-berlin.de!not-for-mail From: "M. Strobel" Newsgroups: comp.lang.php Subject: Re: Magic quotes? Should I still be cautious? Date: Fri, 06 Jan 2012 18:18:35 +0100 Lines: 38 Message-ID: <9moonbF38cU1@mid.uni-berlin.de> References: <4F046877.3080409@arnowelzel.de> <4f05a0b4$0$6924$e4fe514c@news2.news.xs4all.nl> <9mmq09F283U1@mid.uni-berlin.de> Mime-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit X-Trace: news.uni-berlin.de EHUm4ytMDw4w6CzPQs8P8wY5zVYReTp3zU7Q+re2bbq0Baosc= User-Agent: Mozilla/5.0 (X11; U; Linux x86_64; de; rv:1.9.2.24) Gecko/20111101 SUSE/3.1.16 Lightning/1.0b2 Thunderbird/3.1.16 In-Reply-To: Xref: x330-a1.tempe.blueboxinc.net comp.lang.php:4234 Am 06.01.2012 14:32, schrieb Jerry Stuckle: > On 1/6/2012 6:05 AM, Thomas Mlynarczyk wrote: >> Jerry Stuckle schrieb: >> >>> $REQUESTS is quite dangerous. You never know whether it comes >>> from >>> $_GET, $_POST or $_COOKIE, for instance. >> >> True, you don't know. But does it matter? The only problem I >> see is that >> the order of precedence of the three input sources depends on >> the PHP >> configuration, but aside from that, the script is given a >> "foo=bar" and >> a hacker could always send that via any of GET, POST or COOKIE. >> So my >> script should not be dependent on that. I find it rather >> convenient to >> be able to send commands/arguments to my script via any of the >> three >> methods. >> >> Greetings, >> Thomas >> > > No, it doesn't matter if you aren't concerned about security. > I think programming leaves enough room for everybody to use $_GET and $_POST to their liking, but $_REQUEST is no more dangerous than one of GPC. There are some programming mantras you have to keep on saying, this is not one of it. /Str