> > It's a major security hole if left on ;) > And convincing people to plug that hole was not happening, so > something > more major was needed. Only if the programmer uses it. As I understand it, register_globals being on doesn't present a security risk in and of itself as long as the programmer is not relying on its functionality. JM -- PHP General Mailing List (http://www.php.net/) To unsubscribe, visit: http://www.php.net/unsub.php