That's a good point to mention. CSRF is a very common hole in most of the websites on the net today. If you design your application to accept changes of data only through POST (which is what the HTTP specification states), you are less vulnerable to CSRF. But if you use REQUEST everywhere, then what you did is that you allowed all the changes to happen over GET as well, which is very bad.
If you study the HTTP RFC, you will realize when it's better to use POST vs GET. It's arguably that having links as "/user/15/delete" the get requested through GET is a very bad idea, and I agree (although I do it myself sometimes). GET should be used to query information, POST on the other hand should be used to modify information. This is the historical difference :) - Ammar On Dec 5, 2007 3:17 PM, hafez ahmad <[EMAIL PROTECTED]> wrote: > Hi,I agree with Ammar, the misusing of Request may make a security hole, > Foiling > Cross-Site Attacks one of the attacks that might happened by using Request ( > as I think :) ), see this article by Chris Shiflett ( > http://shiflett.org/articles/foiling-cross-site-attacks) .regards, > Hafez > > On Dec 5, 2007 3:04 PM, Ammar Ibrahim < [EMAIL PROTECTED]> wrote: > > > $_REQUEST is not a big no-no. My simple philosophy is: if your data is > > coming from GET, use $_GET, POST use POST but if it comes form both > > (depending on how you design the application) I use $_REQUEST. But generally > > it's always a good idea to minimize the use of $_REQUEST. $_REQUEST itself > > is not a security hole (like register_globals), but it might higher the > > possibility of making a mistake. > > > > register_globals is not the security risk per se, because that sounds > > like none sense. First you need to make a stupid mistake and the attacker > > needs access to the source code in order to be able to exploit it. The > > combination is not very common. But the reason why I hate register_globals > > is a very simple software engineering practice I like to follow; know where > > data is coming from. If I didn't have $_GET, $_POST... etc it would be a > > variable soup that is very hard to trace. > > > > - Ammar > > > > > > On Dec 5, 2007 2:35 PM, Al-Faisal El-Dajani <[EMAIL PROTECTED] > > > wrote: > > > > > Hey Guys, > > > > > > So far my understanding has been that using $_REQUEST is a complete > > > no-no. I've read multiple forum threads explaining how bad things could > > > get, > > > and why not to use them. However, I was recently playing around with > > > SugarCRM, and as far as I can tell, they use it almost exclusively. A list > > > of parameters are sent in _GET, and when there is a form (method being > > > POST > > > of course), hidden input fields are created to create the same parameter > > > list, and all handling is done using _REQUEST. > > > > > > Now, I know I am in no position to bad-mouth SugarCRM, but isn't it > > > bad practice to rely on _request? Could _request ever be considered good? > > > > > > -- > > > Al-Faisal El-Dajani > > > Phone: +962-7-79737050 > > > P.O Box: 140056 > > > 11814 Amman, Jordan > > > > > > > > > > > > > > > -- > Hafez A.Ahmad > Amman-Jordan > mobile:962-785259011 > 962-795708728 > http://blog.hafezadnan.com > > > > --~--~---------~--~----~------------~-------~--~----~ You received this message because you are subscribed to the Google Groups "Jordan PHP Users Group" group. To post to this group, send email to [email protected] To unsubscribe from this group, send email to [EMAIL PROTECTED] For more options, visit this group at http://groups.google.com/group/JoPHP http://Jolug.org/ -~----------~----~----~----~------~----~------~--~---
