tags:

views:

55

answers:

3

I am experienced with web development, but not with PHP. My challenge now is therefore that I am about to move an older PHP solution to a server only supporting PHP 5.2.+. The whole solution is using a $id - style to read the request instead of $_REQUEST['id'] or the $_GET..., $_POST...

I wonder if this type of coding is not longer supported, or if there is something I have missed here. After I moved the solution it is not working. The variable will be blank/empty.

Is there an easy way to solve this, or do I have to rewrite?

Thank you very much if you take the time to help.

+2  A: 

its seam that the older version use Register_globals = on in php.ini

read on it

http://www.peoplecnc.com/register_globals_off.html

its not recommended to use it , and in php5 is off by default,

you can override it by create a file named .htaccess and put this into it:

php_value register_globals 1 

or by put this line in the head of the script (Depreciated in PHP 5.3.0. This deprecated feature will certainly be removed in the future.)

ini_set('register_globals', 'on');

but is not recommended , as you can read in the link.

Haim Evgi
The latter one is ridiculous, man. Try to think, will it ever work.
Col. Shrapnel
@col. thanks i update
Haim Evgi
LOL you still do not understand. **By the time you run this line of code, all initializations already done**.
Col. Shrapnel
The .htaccess solution gives me a 500 server error
Peaceman71
@Peaceman71 well go to error_log and see why
Col. Shrapnel
see if this article help u (step by step how to use in htaccess) http://www.kimvette.org/linux/enabling_register_globals_locally_for_virtual_host
Haim Evgi
if it not work try to put it in this : <IfModule mod_php5.c>php_value .... </IfModule>
Haim Evgi
A: 

The "feature" you describe is called register_globals. It was a failed attempt to make coding easier by magically creating variables from external input. In the end, it only lead to insecure and hard to maintain code. The PHP manual itself warns about it:

http://es.php.net/manual/en/security.globals.php

It's been discouraged for several years now. In PHP/5.2 it was no longer the default setting, in PHP/5.3 it was tagged as deprecated and it's expected to be removed from the language some day.

If you are going to dig into a pile or poorly written old code, you should really make the effort of porting it to the latest PHP version. Otherwise, it'd be better to just configure your server so it can run the legacy code as-is.

To sum up:

  1. If you want to keep the legacy code, enable register globals: http://es.php.net/manual/en/ini.core.php#ini.register-globals

  2. If you want to rewrite the code, install PHP/5.3 in your development box, make sure register_globals is disabled and enable full error reporting: http://es.php.net/manual/en/errorfunc.configuration.php#ini.error-reporting

Update

You apparently need to enable magic quotes as well. Escaping input data for SQL queries is often regarded as a security issue but that's not entirely true: you need to escape input so your app does not crash when the user types a legitimate single quote.

Álvaro G. Vicario
A: 

This style of coding is risky, since variables can be injected into the script by supplying an argument in the URL.

Example:

if(SOME_CONDITION){
    $loggedIn = true;
}

later that same day...

if($loggedIn){
    sensitiveStuff();
}

As you can see, you can fake a login in the code above by adding the argument loggedIn=1 to the URL.

That said, if you know what you are doing, you can easily mimic the old behaviour with the line:

extract($_GET);

for the URL arguments, or

extract($_REQUEST);

for get, post and cookies.

http://php.net/manual/en/function.extract.php

A better way would be to find out exactly what variables are needed and extract only them:

$neededArguments = array('foo', 'bar', 'bla');
foreach($neededArguments as $neededArgument)
    $$neededArgument = $_REQUEST[$neededArgument];
geon
your "risky" example has nothing to do with register_globals. Don't blame language features for problems causes entirely by sloppy coding.
stereofrog