That was enlightening, thank you.  I think that I had better set 
register_globals OFF !  However there is still one last nagging question 
in my mind:  What is the purpose of the $_GET (or $HTTP_GET_VARS) 
predefined variable?  It seems that in the case of "get" variables, 
malicious variables could still be set in the querystring and even using 
$_GET['variablename'] wouldn't be able to stop this from happening.  
That is, from what I understand, the advantage of using "get" variables 
in the first place.

So does using $_GET actually confer any additional security?  If so, how?

