PHP security-global variables and registration
1. Global variable registration
If you can still remember the use of C to develop CGI programs in early WEB application development, You will definitely have a deep understanding of tedious form processing. When PHP's register_globals configuration option is turned on, complex raw form processing no longer exists and public variables are automatically created. It makes PHP programming easy and convenient, but it also brings security risks.
In fact, register_globals is innocent, it does not create vulnerabilities, and it requires developers to make mistakes. However, there are two main reasons why you must turn off register_globals when developing and deploying applications:
First, it increases the number of security vulnerabilities;
Second, it hides the source of the data, which goes against the developer’s responsibility to track data at all times.
All examples in this book assume that register_globals has been turned off and use super public arrays such as $_GET and $_POST instead. Using these arrays is almost as convenient as programming with register_globals turned on, and the slight inconvenience is worth it because it increases the security of your program.
Tips
If you must develop an application that is deployed in an environment where register_globals is turned on, it is important that you All variables must be initialized and error_reporting set to E_ALL(or E_ALL | E_STRICT) to warn about uninitialized variables. When register_globals is turned on, any use of uninitialized variables is almost always a security vulnerability.
The above is the content of PHP security-global variables and registration. For more related content, please pay attention to the PHP Chinese website (www.php.cn)!

Hot AI Tools

Undresser.AI Undress
AI-powered app for creating realistic nude photos

AI Clothes Remover
Online AI tool for removing clothes from photos.

Undress AI Tool
Undress images for free

Clothoff.io
AI clothes remover

AI Hentai Generator
Generate AI Hentai for free.

Hot Article

Hot Tools

Notepad++7.3.1
Easy-to-use and free code editor

SublimeText3 Chinese version
Chinese version, very easy to use

Zend Studio 13.0.1
Powerful PHP integrated development environment

Dreamweaver CS6
Visual web development tools

SublimeText3 Mac version
God-level code editing software (SublimeText3)

Hot Topics



PHP 8.4 brings several new features, security improvements, and performance improvements with healthy amounts of feature deprecations and removals. This guide explains how to install PHP 8.4 or upgrade to PHP 8.4 on Ubuntu, Debian, or their derivati

To work with date and time in cakephp4, we are going to make use of the available FrozenTime class.

CakePHP is an open-source framework for PHP. It is intended to make developing, deploying and maintaining applications much easier. CakePHP is based on a MVC-like architecture that is both powerful and easy to grasp. Models, Views, and Controllers gu

To work on file upload we are going to use the form helper. Here, is an example for file upload.

Validator can be created by adding the following two lines in the controller.

Visual Studio Code, also known as VS Code, is a free source code editor — or integrated development environment (IDE) — available for all major operating systems. With a large collection of extensions for many programming languages, VS Code can be c

CakePHP is an open source MVC framework. It makes developing, deploying and maintaining applications much easier. CakePHP has a number of libraries to reduce the overload of most common tasks.

This tutorial demonstrates how to efficiently process XML documents using PHP. XML (eXtensible Markup Language) is a versatile text-based markup language designed for both human readability and machine parsing. It's commonly used for data storage an
