I just switched to dreamhost and to my horror learned that register_globals is still enabled. I spent an hour researching what others have done with this and haven’t found anything. It seems I cannot switch it off for my site only, and in the knowledge base there is a method of disabling through .htaccess, but I would have to turn off php-cgi which I am not going to do. There was also a way of including some php code in all of your php pages that would clear the globals, but what about php pages I get from others (ie wiki, wordpress)? And I certaintly do not want to change all of my php pages.
I feel very uneasy putting up my site with this enabled, which really only consists of a wordpress blog and some academic papers, but I still don’t like the idea.
So, am I being paranoid or have others found a way to deal with this problem?