News Feed
Jobs Feed
Sections

Recent Jobs

News Archive
Brian Moon's Blog:
Responsible use of the $_REQUEST variable
January 22, 2008 @ 09:38:00

In one of his recent blog entries, Brian Moon takes a look at what he considers the "proper use" of the PHP superglobal $_REQUEST (as brought on by a thread on the PHP internals mailing list.

I have seen more than one person make the following logic mistake: I may get data via GET, I may get data via POST - Ah, I should use $_REQUEST as it will catch both.

Brian points out the error - cookies aren't in $_REQUEST so improper handling of those values could lead to cookie data overwriting GET/POST data from $_REQUEST. Several of the comments on the post also warn against improper handling of the values, noting that doing so could lead to holes open for attacks (like session fixation).

0 comments voice your opinion now!
get post request superglobal cookie security merge



Similar Posts

Job Posting: Digital Business Solutions Seeks Entry Level PHP Website Programmer (Louisville, KY)

JSLabs Blog: How to stop IE from caching AJAX requests

PHP Security Consortium: SecurityFocus Summaries Posted

Site News: Popular Posts for the Week of 01.04.2008

PHPBuilder.com: PHP Filtering with OWASP


Community Events







Don't see your event here?
Let us know!


framework example release cakephp ajax code developer database job book security application zendframework releases mysql PEAR package zend PHP5 conference

All content copyright, 2008 PHPDeveloper.org :: info@phpdeveloper.org - Powered by the Solar PHP Framework