Sec Bug->Req #73359 [Opn]: Bypass desactivated error reporting with set_error_handler()

From: Date: Thu, 20 Oct 2016 20:49:40 +0000
Subject: Sec Bug->Req #73359 [Opn]: Bypass desactivated error reporting with set_error_handler()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-204941@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73359&edit=1 ID: 73359 Updated by: stas@php.net Reported by: me at michelgaschet dot gp Summary: Bypass desactivated error reporting with set_error_handler() Status: Open -Type: Security +Type: Feature/Change Request Package: PHP options/info functions Operating System: All systems PHP Version: 7.0.12 Block user comment: N Private report: Y New Comment: If you can run code on the server, you don't have to do tricks with error handler - you can output and in general do anything error handler does directly from your code. Previous Comments: ------------------------------------------------------------------------ [2016-10-20 19:19:27] me at michelgaschet dot gp Description: ------------ In a system with all error message unactivated for security reason (I.E Production server), it remains possible to reactivate the error messages for a malicious user having the ability to execute code although functions error_reporting()/ini_set() be disabled, with the set_error_handler() is used. Test script: --------------- <?php echo phpversion(); echo "<br />"; function myErrorHandler($errno, $errstr, $errfile, $errline) { var_dump($errno); var_dump($errstr); var_dump($errfile); var_dump($errline); return true; } $old_error_handler = set_error_handler("myErrorHandler"); lolel; ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=73359&edit=1

« previous php.bugs (#204941) next »