douling6469 2009-05-22 12:14
浏览 12
已采纳

通过$ _GET注册位置标头的php安全性

I've got this code on my page:

header("Location: $page");

$page is passed to the script as a GET variable, do I need any security? (if so what)

I was going to just use addslashes() but that would stuff up the URL...

  • 写回答

4条回答 默认 最新

  • dongshushi5579 2009-05-22 12:21
    关注

    I could forward your users anywhere I like if I get them to click a link, which is definitely a big security flaw (Please login on www.yoursite.com?page=badsite.com). Now think of a scenario where badsite.com looks exactly like your site, except that it catches your user's credentials.

    You're better off defining a $urls array in your code and passing only the index to an entry in that array, for example:

    $urls = array(
        'pageName1' => '/link/to/page/number/1',
        'pageNumber2' => '/link/to/page/number/2',
        'fancyPageName3' => '/link/to/page/number/3',
    );
    # Now your URL can look like this:
    # www.yoursite.com?page=pageName1
    
    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论
查看更多回答(3条)

报告相同问题?

悬赏问题

  • ¥30 Matlab打开默认名称带有/的光谱数据
  • ¥50 easyExcel模板 动态单元格合并列
  • ¥15 res.rows如何取值使用
  • ¥15 在odoo17开发环境中,怎么实现库存管理系统,或独立模块设计与AGV小车对接?开发方面应如何设计和开发?请详细解释MES或WMS在与AGV小车对接时需完成的设计和开发
  • ¥15 CSP算法实现EEG特征提取,哪一步错了?
  • ¥15 游戏盾如何溯源服务器真实ip?需要30个字。后面的字是凑数的
  • ¥15 vue3前端取消收藏的不会引用collectId
  • ¥15 delphi7 HMAC_SHA256方式加密
  • ¥15 关于#qt#的问题:我想实现qcustomplot完成坐标轴
  • ¥15 下列c语言代码为何输出了多余的空格