I just read this in my php.ini config file of version 4.1.2. Do you guys implement this as standard procedure in your code ? Accessing variables passed as parameters in the URL as
$foo = $_REQUEST["foo"];
instead of just calling $foo ?
Just want to know if a lot of people are adopting this method.
Thanks !
; - register_globals = Off [Security, Performance]
; Global variables are no longer registered for input data (POST, GET, cookies,
; environment and other server variables). Instead of using $foo, you must use
; you can use $REQUEST["foo"] (includes any variable that arrives through the
; request, namely, POST, GET and cookie variables), or use one of the specific
; $GET["foo"], $POST["foo"], $COOKIE["foo"] or $_FILES["foo"], depending
; on where the input originates. Also, you can look at the
; import_request_variables() function.
; Note that register_globals is going to be depracated (i.e., turned off by
; default) in the next version of PHP, because it often leads to security bugs.
; Read http://php.net/manual/en/security.registerglobals.php for further
; information.