News: When asking for support, it helps us and you, if you read the Posting Guidelines

Login  |  Register
HTML5 Icon HTML5 Icon
TP on Social Media
Welcome, Guest. Please login or register.
Did you miss your activation email?

September 17, 2019, 04:53:31 AM

Login with username, password and session length

Recent

Members
  • Total Members: 3752
  • Latest: Alizee
Stats
  • Total Posts: 188890
  • Total Topics: 20752
  • Online Today: 69
  • Online Ever: 629
  • (November 08, 2018, 01:36:54 PM)
Users Online
Users: 0
Guests: 46
Total: 46

Author Topic: Host configuration question  (Read 6657 times)

0 Members and 1 Guest are viewing this topic.

Offline G6Cad

  • Friends
  • *
  • Posts: 12643
    • FamiljeGodis
Host configuration question
« on: July 31, 2006, 06:47:56 AM »
My host have upgraded the server im using and they have put in some new software and now im wonder about one thing on the new domain settings page i have.
In one place I can set diffrent ways for the server to read PhP, and im lost in one choise i can make there.

Quote

Register globals On Off

"Register Globals" in PHP is "Off" by default. This is for security reasons. Before turning it "On" you should read this documentation, which explains the security risk and consequence concerning this setting.
This is the documentation they point to

Register Globals ON or OFF  ???    What should i set that to? I have read the documentation they have but it soesent really point in any direction for what is the best for what you are using on your webpage.

What should i set that to? On or OFF  :o

Offline IchBin™

  • Developer
  • *
  • Posts: 16228
    • My Website
Re: Host configuration question
« Reply #1 on: July 31, 2006, 07:34:29 AM »
That is not required for any of your stuff to work G6. I have it turned off on my server. Its only a security risk if someone doesn't write good code. :)

akulion

  • Guest
Re: Host configuration question
« Reply #2 on: July 31, 2006, 07:37:00 AM »
yea i saw it in my coppermine installation too -- or was it another script...it told me my global thingies were off and it is recommended they should be on because a bad / weak code could cause a security vunrability

needless to say i didnt turn it on and everything still runs fine

Offline IchBin™

  • Developer
  • *
  • Posts: 16228
    • My Website
Re: Host configuration question
« Reply #3 on: July 31, 2006, 07:38:30 AM »
If you can live with it off, I would recommend that.

akulion

  • Guest
Re: Host configuration question
« Reply #4 on: July 31, 2006, 07:43:59 AM »
Its a good thing u brought this queston up...cos ive always wondered what that setting was

Offline G6Cad

  • Friends
  • *
  • Posts: 12643
    • FamiljeGodis
Re: Host configuration question
« Reply #5 on: July 31, 2006, 08:04:32 AM »
It is set to off :) But why do they have sutch things if it is "dangerous" to have them set to on  :o

Offline IchBin™

  • Developer
  • *
  • Posts: 16228
    • My Website
Re: Host configuration question
« Reply #6 on: July 31, 2006, 08:33:35 AM »
Its only dangersous if the person who writes the scripts doesn't know how to code properly. If the person can code properly there's no danger. Unfortunately, not everyone is a A+ programmer when they start. :)

From what I see, its only dangerous in the sense that if you don't declare a variable (with global on) that it makes it easier for people to inject information into a variable that is not declared, thus making it easier to hack someones site or something.

technodragon73

  • Guest
Re: Host configuration question
« Reply #7 on: July 31, 2006, 08:35:30 AM »
I couldn't tell you anything about the dangerous part, but i do know that it caused an issue being of on someone's server that I was attempting install oscommerce for...once turned on it worked perfectly.

Offline IchBin™

  • Developer
  • *
  • Posts: 16228
    • My Website
Re: Host configuration question
« Reply #8 on: July 31, 2006, 08:41:14 AM »
If they use registered globals then yes, it will have to be turned on. I've ran into that before too. I can't remember which script required it. Its really a personal preference I guess. But I tend to think the more you have open, the less secure your site is. I try to keep things like that at a minimum if at all possible.

akulion

  • Guest
Re: Host configuration question
« Reply #9 on: July 31, 2006, 08:49:17 AM »
reminds me of my lst host...they had an over sized red button which said "Delete this account"

lool anyways i did get to press it once :D thats when i was leaving them