Just a point
$_REQUEST is not only $_GET & $_POST, it's also contains $_COOKIE.
for me, my philosophy is that there is nothing as not not not, it's just
that some stuff should be used responsibly, also security is always an
issue, the only thing that the type of application enforces, is the need to
use https or http, but other than that, it's all the same.

On Dec 5, 2007 4:36 PM, zaid emeish <[EMAIL PROTECTED]> wrote:

> This is one of my fav topics. I struggled alot with securing my
> applications. and I wanted to close every possible whole that might cause
> any issues. but i came to realize that the application decides the lvl of
> security. not the developer. so look at the purpose your application is
> serving. if sensitive data is involved. then add complex checks and restrict
> incoming and outgoing data. if not. then add adequate security checks. using
> _REQUEST is not bad. just a better practice is to specify _GET or _POST. and
> it just adds more clarity to your application.
>
> but if you are obsessed with PHP security. google it. there are amazing
> tutorials on the internet. from escaping to adding hashes and check sums. to
> encryption.
>
> Regards
> --Z
>
>
> On Dec 5, 2007 8:46 AM, Al-Faisal El-Dajani <[EMAIL PROTECTED]>
> wrote:
>
> > Excellent link Hafez, thanx for sharing.
> >
> > On Dec 5, 2007 3:17 PM, hafez ahmad <[EMAIL PROTECTED]> wrote:
> >
> > > Hi,I agree with Ammar, the misusing of Request may make a security
> > > hole, Foiling Cross-Site Attacks one of the attacks that might
> > > happened by using Request ( as I think :) ), see this article by Chris
> > > Shiflett ( http://shiflett.org/articles/foiling-cross-site-attacks) .
> > > regards,
> > > Hafez
> > >
> > > On Dec 5, 2007 3:04 PM, Ammar Ibrahim < [EMAIL PROTECTED]>
> > > wrote:
> > >
> > > > $_REQUEST is not a big no-no. My simple philosophy is: if your data
> > > > is coming from GET, use $_GET, POST use POST but if it comes form both
> > > > (depending on how you design the application) I use $_REQUEST. But 
> > > > generally
> > > > it's always a good idea to minimize the use of $_REQUEST. $_REQUEST 
> > > > itself
> > > > is not a security hole (like register_globals), but it might higher the
> > > > possibility of making a mistake.
> > > >
> > > >  register_globals is not the security risk per se, because that
> > > > sounds like none sense. First you need to make a stupid mistake and the
> > > > attacker needs access to the source code in order to be able to exploit 
> > > > it.
> > > > The combination is not very common. But the reason why I hate
> > > > register_globals is a very simple software engineering practice I like 
> > > > to
> > > > follow; know where data is coming from. If I didn't have $_GET, 
> > > > $_POST...
> > > > etc it would be a variable soup that is very hard to trace.
> > > >
> > > > - Ammar
> > > >
> > > >
> > > > On Dec 5, 2007 2:35 PM, Al-Faisal El-Dajani <[EMAIL PROTECTED]
> > > > > wrote:
> > > >
> > > > > Hey Guys,
> > > > >
> > > > > So far my understanding has been that using $_REQUEST is a
> > > > > complete no-no. I've read multiple forum threads explaining how bad 
> > > > > things
> > > > > could get, and why not to use them. However, I was recently playing 
> > > > > around
> > > > > with SugarCRM, and as far as I can tell, they use it almost 
> > > > > exclusively. A
> > > > > list of parameters are sent in _GET, and when there is a form (method 
> > > > > being
> > > > > POST of course), hidden input fields are created to create the same
> > > > > parameter list, and all handling is done using _REQUEST.
> > > > >
> > > > > Now, I know I am in no position to bad-mouth SugarCRM, but isn't
> > > > > it bad practice to rely on _request? Could _request ever be 
> > > > > considered good?
> > > > >
> > > > > --
> > > > > Al-Faisal El-Dajani
> > > > > Phone: +962-7-79737050
> > > > > P.O Box: 140056
> > > > > 11814 Amman, Jordan
> > > > >
> > > > >
> > > >
> > > >
> > > >
> > >
> > >
> > > --
> > > Hafez A.Ahmad
> > > Amman-Jordan
> > > mobile:962-785259011
> > >           962-795708728
> > > http://blog.hafezadnan.com
> > >
> > >
> > >
> >
> >
> > --
> > Al-Faisal El-Dajani
> > Phone: +962-7-79737050
> > P.O Box: 140056
> > 11814 Amman, Jordan
> >
> >
>
> >
>


-- 
                                Ala'a A. Ibrahim
http://guru.alaa-ibrahim.com/

--~--~---------~--~----~------------~-------~--~----~
You received this message because you are subscribed to the Google Groups 
"Jordan PHP Users Group" group.
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to [EMAIL PROTECTED]
For more options, visit this group at http://groups.google.com/group/JoPHP
http://Jolug.org/
-~----------~----~----~----~------~----~------~--~---

Reply via email to