Path: csiph.com!x330-a1.tempe.blueboxinc.net!usenet.pasdenom.info!gegeweb.org!de-l.enfer-du-nord.net!feeder1.enfer-du-nord.net!fu-berlin.de!uni-berlin.de!not-for-mail From: "M. Strobel" Newsgroups: comp.lang.php Subject: Re: Magic quotes? Should I still be cautious? Date: Fri, 06 Jan 2012 20:24:36 +0100 Lines: 44 Message-ID: <9mp03kFtldU1@mid.uni-berlin.de> References: <4F046877.3080409@arnowelzel.de> <4f05a0b4$0$6924$e4fe514c@news2.news.xs4all.nl> <9mmq09F283U1@mid.uni-berlin.de> Mime-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit X-Trace: news.uni-berlin.de qDMm5goMaiTI8ejImcEVlw2cOZbqdiGlElQOTBV6EWqOsb49Q= User-Agent: Mozilla/5.0 (X11; U; Linux x86_64; de; rv:1.9.2.24) Gecko/20111101 SUSE/3.1.16 Lightning/1.0b2 Thunderbird/3.1.16 In-Reply-To: Xref: x330-a1.tempe.blueboxinc.net comp.lang.php:4240 Am 06.01.2012 20:14, schrieb Thomas Mlynarczyk: > Jerry Stuckle schrieb: >> On 1/6/2012 6:05 AM, Thomas Mlynarczyk wrote: >>> Jerry Stuckle schrieb: >>> >>>> $REQUESTS is quite dangerous. You never know whether it comes >>>> from >>>> $_GET, $_POST or $_COOKIE, for instance. >>> >>> True, you don't know. But does it matter? >> >> No, it doesn't matter if you aren't concerned about security. > > I was hoping for some objective arguments, but well... > > Okay, let me rephrase this. Suppose you have a parameter foo > which is expected to be sent via $_POST only. So if it's being > sent via $_GET you refuse it as invalid. Okay. So all the > attacker has to do is send it via $_POST and you will happily > accept it. Now of course you must ensure that this foo parameter, > even if sent via $_POST, can do no evil. You must properly > validate it. But once you're there, you might as well accept it > via $_GET, for what difference does it make now? You validate it, > so it can do no harm. > > I repeat: An attacker can send ANYTHING via GET or POST or COOKIE > as he chooses. YOU, therefore, cannot say "this came via POST as > intended, so it's safe". You must not rely on the data source. > Therefor, the data source should be irrelevant to your > application and your application must be designed so that it > doesn't matter if the data comes via GET, POST or COOKIE. In > other words: When some evil person knocks on your door, it really > doesn't matter if he came by train or by car to your doorstep. > The same holds for a nice guy visiting you. > > Greetings, > Thomas > Quite near to a mathematical proof. /Str. To your signature: Dans ce cas ceux qui ont tort ne sont pas nombreux.