This is one of my fav topics. I struggled alot with securing my applications. and I wanted to close every possible whole that might cause any issues. but i came to realize that the application decides the lvl of security. not the developer. so look at the purpose your application is serving. if sensitive data is involved. then add complex checks and restrict incoming and outgoing data. if not. then add adequate security checks. using _REQUEST is not bad. just a better practice is to specify _GET or _POST. and it just adds more clarity to your application.
but if you are obsessed with PHP security. google it. there are amazing tutorials on the internet. from escaping to adding hashes and check sums. to encryption. Regards --Z On Dec 5, 2007 8:46 AM, Al-Faisal El-Dajani <[EMAIL PROTECTED]> wrote: > Excellent link Hafez, thanx for sharing. > > On Dec 5, 2007 3:17 PM, hafez ahmad <[EMAIL PROTECTED]> wrote: > > > Hi,I agree with Ammar, the misusing of Request may make a security hole, > > Foiling Cross-Site Attacks one of the attacks that might happened by > > using Request ( as I think :) ), see this article by Chris Shiflett ( > > http://shiflett.org/articles/foiling-cross-site-attacks) .regards, > > Hafez > > > > On Dec 5, 2007 3:04 PM, Ammar Ibrahim < [EMAIL PROTECTED]> wrote: > > > > > $_REQUEST is not a big no-no. My simple philosophy is: if your data is > > > coming from GET, use $_GET, POST use POST but if it comes form both > > > (depending on how you design the application) I use $_REQUEST. But > > > generally > > > it's always a good idea to minimize the use of $_REQUEST. $_REQUEST itself > > > is not a security hole (like register_globals), but it might higher the > > > possibility of making a mistake. > > > > > > register_globals is not the security risk per se, because that sounds > > > like none sense. First you need to make a stupid mistake and the attacker > > > needs access to the source code in order to be able to exploit it. The > > > combination is not very common. But the reason why I hate register_globals > > > is a very simple software engineering practice I like to follow; know > > > where > > > data is coming from. If I didn't have $_GET, $_POST... etc it would be a > > > variable soup that is very hard to trace. > > > > > > - Ammar > > > > > > > > > On Dec 5, 2007 2:35 PM, Al-Faisal El-Dajani <[EMAIL PROTECTED] > > > > wrote: > > > > > > > Hey Guys, > > > > > > > > So far my understanding has been that using $_REQUEST is a complete > > > > no-no. I've read multiple forum threads explaining how bad things could > > > > get, > > > > and why not to use them. However, I was recently playing around with > > > > SugarCRM, and as far as I can tell, they use it almost exclusively. A > > > > list > > > > of parameters are sent in _GET, and when there is a form (method being > > > > POST > > > > of course), hidden input fields are created to create the same parameter > > > > list, and all handling is done using _REQUEST. > > > > > > > > Now, I know I am in no position to bad-mouth SugarCRM, but isn't it > > > > bad practice to rely on _request? Could _request ever be considered > > > > good? > > > > > > > > -- > > > > Al-Faisal El-Dajani > > > > Phone: +962-7-79737050 > > > > P.O Box: 140056 > > > > 11814 Amman, Jordan > > > > > > > > > > > > > > > > > > > > > > > -- > > Hafez A.Ahmad > > Amman-Jordan > > mobile:962-785259011 > > 962-795708728 > > http://blog.hafezadnan.com > > > > > > > > > -- > Al-Faisal El-Dajani > Phone: +962-7-79737050 > P.O Box: 140056 > 11814 Amman, Jordan > > > --~--~---------~--~----~------------~-------~--~----~ You received this message because you are subscribed to the Google Groups "Jordan PHP Users Group" group. To post to this group, send email to [email protected] To unsubscribe from this group, send email to [EMAIL PROTECTED] For more options, visit this group at http://groups.google.com/group/JoPHP http://Jolug.org/ -~----------~----~----~----~------~----~------~--~---
