Skip to content
View in the app

A better way to browse. Learn more.

Web Designer Forum

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Epic PHP Problem!

Featured Replies

Thanks for your help - all sorted now!

That is indeed a lot of code :D

A couple of tips to help you debug this:

 

1. Instead of all those $_POST assignments:

$title = $_POST['title'];

you can put this at the top of your php file:

foreach ($_POST as $key => $value)
{
//you can echo them to help you debug the script
echo "Posted field:".$key."| Value:".$value."<br />";
//set a variable with the name of the posted field and assign the posted value
$$key = $value; //so an input with the name of title will become $title
}
//stop script execution
exit;

Noooooooo!!! Mihai you fool!

 

What you are doing is turning autoglobals on - if you google "PHP Autoglobals" you will find a few million blog posts on why they are bad.

 

Don't follow Mihai's advice, unless you like having your scripts hax0rd

Penguin ... i think you got me wrong. I agree that using/echoing $_POST without proper "input sanitation" is bad, if that's what you meant by "autoglobals" (Google didn't prove to be much of a help on that).

Would you care to elaborate on the autoglobals/fool issue, did you mean superglobals ?

  • Author

Thank you for your input Mihai but im probably gonna stick to the way I have coded it as iv done it all now.

I think php_penguin was referring to this register_globals

 

@PHP_Penguin do you have any suggestions of why my form isnt working? its driving me nuts now and could do with another set of eyes (and more knowledge) on it! :D

Two simple things to check.

 

1. Is the php script saved as "applying.php" as the form calls it and is it in the right location?

2. Check your error file for messages, this may give a clue as to the problem?

 

Another thing to do is just make applying.php contain

<?php
echo "Hello World";
?>

 

and then try:

<?php
echo "Hello ".  $_POST['first'];
?>

 

as this will tell you if the script is being executed or if the problem comes before that, and then make sure the data is getting through, etc...

Noooooooo!!! Mihai you fool!

 

What you are doing is turning autoglobals on - if you google "PHP Autoglobals" you will find a few million blog posts on why they are bad.

 

Don't follow Mihai's advice, unless you like having your scripts hax0rd

Calling someone a fool is pretty harsh - particularly when you're wrong.

 

Mihai was looping through the POST superglobal and assigning each array to a varible.

 

You're referring to the functionality of register_globals which takes input from all sources (in GPC order) to create its own variables. While this is inherently bad, in this case wouldn't make the blindest bit of difference because there's no sanitisation anyway.

 

 

Duck - on the line after the opening <? put: error_reporting(E_ALL); and see what errors it gives.. much easier than going through all that code to spot it manually ;)

 

Edit: or check your error log as Eris suggests.. :)

  • Author

.

I thought that might be it. Basically, you can only use header() before other output - although in your case it might simply be the blank lines causing it because you're not outputting anything... see: http://uk3.php.net/header

Remember that header() must be called before any actual output is sent, either by normal HTML tags, blank lines in a file, or from PHP. It is a very common error to read code with include(), or require(), functions, or another file access function, and have spaces or empty lines that are output before header() is called. The same problem exists when using a single PHP/HTML file.

 

Your undefined index errors means you're using array elements that haven't been set - it'd be easier to diagnose if we could see booking.php, or just parts of it..

if (!isset($_POST['email'])) {

header( "Location: $formurl" );

exit;

}

if (empty($email)) {

  header( "Location: $errorurl" );

  exit;

}

 

I think it was because these two lines do the same thing? They both check for $email, one redirects to $formurl and the other to $errorurl. You should only have one!?

  • Author

Ahhhhh I see now! thanks Eris your a star! :D

I think php_penguin was referring to the $$ assign combined with the POST fields. Not sure exactly how you cand manipulate that into haxoring ... but if you don't compare it to a list of predefined/allowed POST fields, things can go wrong. So here's a better example:

foreach ($_POST as $key => $value)
{
//you can echo them to help you debug the script
echo "Posted field:".$key."| Value:".$value."<br />";
//predefined fields
  $allowed_fields = array('title','description','etc'); 
// check if POST field is in the allowed array
  if (in_array($key,$allowed_fields))
  {
//set a variable with the name of the posted field and assign the posted value
$$key = $value; //so an input with the name of title will become $title
}
}
//this way the attacker can't add any other custom fields and is still better than writing all that code

On a side note duck, you could just outsource all instances of this to your css file too, will make the form load quicker.

 

<p style='font-size:10pt;padding:0 2%;'>

@Mihai - even a script that allows only predefined fields is still open to malicious use if there's no sanitisation.

Create an account or sign in to comment

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.