Halaman

    Social Items

php Juggling

this condition is called "Juggling".
 // in_array()  
 var_dump(in_array(true,$ar));  // true
 var_dump(in_array(1,$ar)); // true
 // == condition
 var_dump(0 == 'password') // true
 var_dump(true == 'password') // true
// example
 function example($password){
    if($password == 'password'){
        return true;
      } else {
        return false;
      }
  }
  var_dump(example(0)); // bool true
  var_dump(example(true)); // bool true
  var_dump(example('password')); // bool true
  var_dump(example(1)); // bool false
  
source : https://www.netsparker.com/blog/web-security/php-type-juggling-vulnerabilities/

Tidak ada komentar