Welcome to the JaguarPC Community
JaguarPC
Sales: (888) 338-5261
Support: (888)-551-3050
Results 1 to 15 of 15

This is a discussion on register_globals in the VPS & Dedicated forum
One of my mates wants me to turn register_globals settings on, but last time i did this it cause all sorts of problems, i was ...

  1. #1
    Loyal Client
    Join Date
    Nov 2007
    Location
    UK
    Posts
    281

    register_globals

    One of my mates wants me to turn register_globals settings on, but last time i did this it cause all sorts of problems, i was just looking for some other views on the matter.

  2. #2
    the Windlord Gwaihir's Avatar
    Join Date
    Jun 2002
    Posts
    2,562
    Eh.. why would he want that?
    Regards,

    Wim Heemskerk
    ---
    Visit MeCCG.net - Cardgaming in J.R.R. Tolkien's Middle-earth
    And Gwaihir.net - The Middle-earth CCG store

  3. #3
    Not A Senior Member homoludens's Avatar
    Join Date
    Sep 2005
    Location
    H-Town
    Posts
    582
    Off! Off! Off!

    Etc.

  4. #4
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    Tell your mate to rewrite his ^%$& code...

    Dude, this is like soooo 2006!

    Hackers will eat your mate alive, assuming they know he's alive...
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  5. #5
    Loyal Client
    Join Date
    Nov 2007
    Location
    UK
    Posts
    281
    Quote Originally Posted by Vin DSL View Post
    Tell your mate to rewrite his ^%$& code...

    Dude, this is like soooo 2006!

    Hackers will eat your mate alive, assuming they know he's alive...
    I know i told him, but i need some sort of technicial jarggon to get him with.

    Any ideas Vin?

  6. #6
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  7. #7
    the Windlord Gwaihir's Avatar
    Join Date
    Jun 2002
    Posts
    2,562
    And tell him he should follow up on the note on superglobals at the bottom if he wants to know how easy it is to do without register_globals.
    Regards,

    Wim Heemskerk
    ---
    Visit MeCCG.net - Cardgaming in J.R.R. Tolkien's Middle-earth
    And Gwaihir.net - The Middle-earth CCG store

  8. #8
    Not A Senior Member homoludens's Avatar
    Join Date
    Sep 2005
    Location
    H-Town
    Posts
    582
    Quote Originally Posted by Vin DSL
    Dude, this is like soooo 2006!
    Not quite.

    Quote Originally Posted by RickWeb
    One of my mates wants me to turn register_globals settings on, but last time i did this it cause all sorts of problems.
    You can emulate register_globals anyway. Just don't.

  9. #9
    Loyal Client
    Join Date
    Nov 2007
    Location
    UK
    Posts
    281
    This is the response i get

    Quote Originally Posted by Adam
    Hey Rick,


    It isn't really an issue of my coding to be honest, it's an open source package and I don't really fancy trying to write an e-commerce program in PHP. Having register_globals turned off makes almost everything in Fantastico useless and I think trying to tweak the whole OS Commerce package to accommodate a server without register_globals wouldn't even be worth trying.


    Is there no other way around this? What sort of security risks would be posed by having this feature turned on? Would this put just the domain at risk, or the entire server?


    Regards,
    Adam

  10. #10
    Not A Senior Member homoludens's Avatar
    Join Date
    Sep 2005
    Location
    H-Town
    Posts
    582
    There are community fixes for running osCommerce with register_globals off. I wouldn't want to comment on whether they are secure or not.

  11. #11
    Loyal Client the_ancient's Avatar
    Join Date
    Feb 2004
    Posts
    3,386
    Quote Originally Posted by homoludens View Post
    There are community fixes for running osCommerce with register_globals off. I wouldn't want to comment on whether they are secure or not.
    as of 2.2RC1 it should not be a issuse

    http://forums.oscommerce.com/index.php?showtopic=268335
    -------------------------
    the_ancient
    MP Technology Group

  12. #12
    the Windlord Gwaihir's Avatar
    Join Date
    Jun 2002
    Posts
    2,562
    Quote Originally Posted by RickWeb View Post
    Having register_globals turned off makes almost everything in Fantastico useless
    Yet we have Fantastico and it works without a hitch..

    Sorry to say it, but he is really years behind the times.

    and I think trying to tweak the whole OS Commerce package to accommodate a server without register_globals wouldn't even be worth trying.
    Right; it might take.. wow.. a whole minute longer than typing that e-mail?

    Surely, like any application, OS Commerce includes some form of utitily script in each and every page. All it would take is to add the emulation homoludens pointed out at the top of that script. This is obviously still not a great way to go, but at least limits the risks to the one outdated application that actually uses it.

    Is there no other way around this? What sort of security risks would be posed by having this feature turned on? Would this put just the domain at risk, or the entire server?
    That depends on whether you run PHP in CGI mode (with seperate users), or as a module (with one php user for the whole server / VPS). In the first case it would risk the account, in the latter case the whole server / VPS.
    Regards,

    Wim Heemskerk
    ---
    Visit MeCCG.net - Cardgaming in J.R.R. Tolkien's Middle-earth
    And Gwaihir.net - The Middle-earth CCG store

  13. #13
    Loyal Client
    Join Date
    Nov 2007
    Location
    UK
    Posts
    281
    I will set he straight next time.

  14. #14
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    Quote Originally Posted by Gwaihir View Post
    Sorry to say it, but he is really years behind the times...
    Thank you!!!
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  15. #15
    Community Leader jason's Avatar
    Join Date
    Sep 2001
    Location
    Rochester, NY
    Posts
    6,003
    You can enable register_globals in just the directories used by OS Commerce via an Apache directive (if using mod_php) or custom php.ini file(s) is using PHP-CGI.

    Disable register_globals for the whole site/server, then in the OS Commerce directory just add this to the .htaccess file if using mod_php:

    Code:
    php_flag register_globals on
    or, if using PHP-CGI, copy your main php.ini file to the directory where OS Commerce is installed and change the register_globals setting of the copy.

    --Jason
    Jason Pitoniak
    Interbrite Communications
    www.interbrite.com www.kodiakskorner.com

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •