Excellent link Hafez, thanx for sharing.

On Dec 5, 2007 3:17 PM, hafez ahmad <[EMAIL PROTECTED]> wrote:

> Hi,I agree with Ammar, the misusing of Request may make a security hole, 
> Foiling
> Cross-Site Attacks one of the attacks that might happened by using Request (
> as I think :) ), see this article by Chris Shiflett (
> http://shiflett.org/articles/foiling-cross-site-attacks) .regards,
> Hafez
>
> On Dec 5, 2007 3:04 PM, Ammar Ibrahim < [EMAIL PROTECTED]> wrote:
>
> > $_REQUEST is not a big no-no. My simple philosophy is: if your data is
> > coming from GET, use $_GET, POST use POST but if it comes form both
> > (depending on how you design the application) I use $_REQUEST. But generally
> > it's always a good idea to minimize the use of $_REQUEST. $_REQUEST itself
> > is not a security hole (like register_globals), but it might higher the
> > possibility of making a mistake.
> >
> >  register_globals is not the security risk per se, because that sounds
> > like none sense. First you need to make a stupid mistake and the attacker
> > needs access to the source code in order to be able to exploit it. The
> > combination is not very common. But the reason why I hate register_globals
> > is a very simple software engineering practice I like to follow; know where
> > data is coming from. If I didn't have $_GET, $_POST... etc it would be a
> > variable soup that is very hard to trace.
> >
> > - Ammar
> >
> >
> > On Dec 5, 2007 2:35 PM, Al-Faisal El-Dajani <[EMAIL PROTECTED] >
> > wrote:
> >
> > > Hey Guys,
> > >
> > > So far my understanding has been that using $_REQUEST is a complete
> > > no-no. I've read multiple forum threads explaining how bad things could 
> > > get,
> > > and why not to use them. However, I was recently playing around with
> > > SugarCRM, and as far as I can tell, they use it almost exclusively. A list
> > > of parameters are sent in _GET, and when there is a form (method being 
> > > POST
> > > of course), hidden input fields are created to create the same parameter
> > > list, and all handling is done using _REQUEST.
> > >
> > > Now, I know I am in no position to bad-mouth SugarCRM, but isn't it
> > > bad practice to rely on _request? Could _request ever be considered good?
> > >
> > > --
> > > Al-Faisal El-Dajani
> > > Phone: +962-7-79737050
> > > P.O Box: 140056
> > > 11814 Amman, Jordan
> > >
> > >
> >
> >
> >
>
>
> --
> Hafez A.Ahmad
> Amman-Jordan
> mobile:962-785259011
>           962-795708728
> http://blog.hafezadnan.com
>
> >
>


-- 
Al-Faisal El-Dajani
Phone: +962-7-79737050
P.O Box: 140056
11814 Amman, Jordan

--~--~---------~--~----~------------~-------~--~----~
You received this message because you are subscribed to the Google Groups 
"Jordan PHP Users Group" group.
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to [EMAIL PROTECTED]
For more options, visit this group at http://groups.google.com/group/JoPHP
http://Jolug.org/
-~----------~----~----~----~------~----~------~--~---

Reply via email to