Bug #67356 [Com]: php loophole GBK
| From: | xiaobianmail at 126 dot com | Date: | Fri, 13 Jun 2014 04:53:19 +0000 |
| Subject: | Bug #67356 [Com]: php loophole GBK | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-186170@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=67356&edit=1
ID: 67356
Comment by: xiaobianmail at 126 dot com
Reported by: xiaobianmail at 126 dot com
Summary: php loophole GBK
Status: Not a bug
Type: Bug
Package: *General Issues
Operating System: linux
PHP Version: 5.5.12
Block user comment: N
Private report: N
New Comment:
5c problemï¼CP936ãShift_JISãwindows-31jãsjisãMS932ãEUC_JPï¼
For PHP security, I can only use the mbstring.
Previous Comments:
------------------------------------------------------------------------
[2014-05-29 08:05:52] requinix@php.net
As you've seen, CP936 (which supports GBK) encodes é as Ã\. This results in the
characters
var_dump("Ã\") // 0xDF 0x5C
and the unterminated string is what PHP is complaining about.
Fun fact: that problem right there is why CP936 is one of the very few encodings that allows SQL
injection via Unicode.
CP936 just isn't safe. Use a different encoding in your console or find another way to
represent that character (and the others like it) in code.
------------------------------------------------------------------------
[2014-05-29 05:44:03] xiaobianmail at 126 dot com
My solution ï¼
1.str_replace("\\", " ", "XXXXXX");
2.mb_substr("XXXXXX", 0, 1, "gbk");
------------------------------------------------------------------------
[2014-05-29 03:38:43] xiaobianmail at 126 dot com
php 5.3 5.4 5.5 ....ALL Version
linux windows
------------------------------------------------------------------------
[2014-05-29 03:33:33] xiaobianmail at 126 dot com
Description:
------------
When the page encoding is gbk, this code will be fatal error.
>php -r 'var_dump("é");'
Parse error: syntax error, unexpected end of file, expecting variable (T_VARIABLE) or ${
(T_DOLLAR_OPEN_CURLY_BRACES) or {$ (T_CURLY_OPEN) in Command line code on line 1
Test script:
---------------
>php -r 'var_dump("é");'
Parse error: syntax error, unexpected end of file, expecting variable (T_VARIABLE) or ${
(T_DOLLAR_OPEN_CURLY_BRACES) or {$ (T_CURLY_OPEN) in Command line code on line 1
<?php
//126 GBK error
$count = $count2 = 0;
for($h = hexdec("8100"); $h <= hexdec("fe00"); $h = $h + 256){
$i=0;
for($l=hexdec("0040");$l<=hexdec("00fe");$l++){
$char16 = dechex($h+$l);
if(substr($char16,2,2) == '5c'){
echo pack("n*",$h+$l)."<br />";
$count2++;
}
$i++;
$count++;
}
}
echo $count;
echo"<br />";
echo $count2;
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=67356&edit=1