May 8, 200818 yr That is indeed a lot of code A couple of tips to help you debug this: 1. Instead of all those $_POST assignments: $title = $_POST['title']; you can put this at the top of your php file: foreach ($_POST as $key => $value) { //you can echo them to help you debug the script echo "Posted field:".$key."| Value:".$value."<br />"; //set a variable with the name of the posted field and assign the posted value $$key = $value; //so an input with the name of title will become $title } //stop script execution exit;
May 8, 200818 yr Noooooooo!!! Mihai you fool! What you are doing is turning autoglobals on - if you google "PHP Autoglobals" you will find a few million blog posts on why they are bad. Don't follow Mihai's advice, unless you like having your scripts hax0rd
May 8, 200818 yr Penguin ... i think you got me wrong. I agree that using/echoing $_POST without proper "input sanitation" is bad, if that's what you meant by "autoglobals" (Google didn't prove to be much of a help on that). Would you care to elaborate on the autoglobals/fool issue, did you mean superglobals ?
May 9, 200818 yr Author Thank you for your input Mihai but im probably gonna stick to the way I have coded it as iv done it all now. I think php_penguin was referring to this register_globals @PHP_Penguin do you have any suggestions of why my form isnt working? its driving me nuts now and could do with another set of eyes (and more knowledge) on it!
May 9, 200818 yr Two simple things to check. 1. Is the php script saved as "applying.php" as the form calls it and is it in the right location? 2. Check your error file for messages, this may give a clue as to the problem? Another thing to do is just make applying.php contain <?php echo "Hello World"; ?> and then try: <?php echo "Hello ". $_POST['first']; ?> as this will tell you if the script is being executed or if the problem comes before that, and then make sure the data is getting through, etc...
May 9, 200818 yr Noooooooo!!! Mihai you fool! What you are doing is turning autoglobals on - if you google "PHP Autoglobals" you will find a few million blog posts on why they are bad. Don't follow Mihai's advice, unless you like having your scripts hax0rd Calling someone a fool is pretty harsh - particularly when you're wrong. Mihai was looping through the POST superglobal and assigning each array to a varible. You're referring to the functionality of register_globals which takes input from all sources (in GPC order) to create its own variables. While this is inherently bad, in this case wouldn't make the blindest bit of difference because there's no sanitisation anyway. Duck - on the line after the opening <? put: error_reporting(E_ALL); and see what errors it gives.. much easier than going through all that code to spot it manually Edit: or check your error log as Eris suggests..
May 9, 200818 yr I thought that might be it. Basically, you can only use header() before other output - although in your case it might simply be the blank lines causing it because you're not outputting anything... see: http://uk3.php.net/header Remember that header() must be called before any actual output is sent, either by normal HTML tags, blank lines in a file, or from PHP. It is a very common error to read code with include(), or require(), functions, or another file access function, and have spaces or empty lines that are output before header() is called. The same problem exists when using a single PHP/HTML file. Your undefined index errors means you're using array elements that haven't been set - it'd be easier to diagnose if we could see booking.php, or just parts of it..
May 9, 200818 yr if (!isset($_POST['email'])) { header( "Location: $formurl" ); exit; } if (empty($email)) { header( "Location: $errorurl" ); exit; } I think it was because these two lines do the same thing? They both check for $email, one redirects to $formurl and the other to $errorurl. You should only have one!?
May 9, 200818 yr I think php_penguin was referring to the $$ assign combined with the POST fields. Not sure exactly how you cand manipulate that into haxoring ... but if you don't compare it to a list of predefined/allowed POST fields, things can go wrong. So here's a better example: foreach ($_POST as $key => $value) { //you can echo them to help you debug the script echo "Posted field:".$key."| Value:".$value."<br />"; //predefined fields $allowed_fields = array('title','description','etc'); // check if POST field is in the allowed array if (in_array($key,$allowed_fields)) { //set a variable with the name of the posted field and assign the posted value $$key = $value; //so an input with the name of title will become $title } } //this way the attacker can't add any other custom fields and is still better than writing all that code
May 9, 200818 yr On a side note duck, you could just outsource all instances of this to your css file too, will make the form load quicker. <p style='font-size:10pt;padding:0 2%;'>
May 9, 200818 yr @Mihai - even a script that allows only predefined fields is still open to malicious use if there's no sanitisation.
Create an account or sign in to comment