3 ms·
Yet another reason eval is evil and should be in disable_functions : http://php.net/manual/en/ini.core.php#ini.disable-functions http://php.net/manual/en/ini.co
by eksith 13y ago
Yet another reason eval is evil and should be in disable_functions : http://php.net/manual/en/ini.core.php#ini.disable-functions http://php.net/manual/en/ini.core.php#ini.disable-functions
Better yet, if you're on a nix box, you should be using http://www.hardened-php.net/suhosin/ http://www.hardened-php.net/suhosin/ There are some potential hiccups with off-the-shelf software, but some minor inconvenience is a better alternative than having your system compromised.
- mappu 13y agoNote that there's no suhosin for PHP5.4, and therefore it no longer appears in the Wheezy repositories.
- eksith 13y agoYes, this is a concern. I believe the latest version with the patch is 5.3.21 which is included with OpenBSD. But some of the features in Suhosin were merged into mainline PHP. It would be interesting to see a side-by-side of 5.4 and Suhoshin patched features. I'd still advise people writing new applications to go with PHP 5.4 first if only because development is made simpler, therefore it's less likely to include accidental vulnerabilities while trying to (re)implement new features available by default in 5.4.
- meowface 13y agoBelieve it or not, this code would be just as bad even if the `eval` call was removed entirely. See: http://www.reddit.com/r/netsec/comments/1k1875/open_source_backdoor_copyrighted_under_gnu_gpl/cbkjgzj http://www.reddit.com/r/netsec/comments/1k1875/open_source_b... I'm not sure if Suhosin also prevents implicit evals of that nature; it very well may. And if it doesn't, this code could effectively be neutralized if only harmless functions could be called (though it'd be hard to guarantee such a thing).
- eksith 13y agoWow! That's just... nuts! I had no idea that PHP had such a completely insecure inclusion vulnerability. I'm not sure if Suhosin protects against these, but the feature list does mention limits on request variables : http://www.hardened-php.net/suhosin/a_feature_list.html http://www.hardened-php.net/suhosin/a_feature_list.html As always, yes, it's very difficult to guarantee only harmless functions are called. One of the simplest ways would be to prevent execution of code in the web root directory. Usually, we put the code files outside www and disable file uploads (separate instance for that which will exclusively handle PUT requests).
- meowface 13y agoTo be fair, it's probably not a security vulnerability in most cases, because it's rare that serious code does the equivalent of `$func = $_GET['func']; $func($_GET['userinput']);`, but it certainly makes for nice backdooring. Regardless, PHP in general was never designed for security of any sort.