Sec Bug->Req #73359 [Opn]: Bypass desactivated error reporting with set_error_handler()
| From: | stas@php.net | Date: | Thu, 20 Oct 2016 20:49:40 +0000 |
| Subject: | Sec Bug->Req #73359 [Opn]: Bypass desactivated error reporting with set_error_handler() | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-204941@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73359&edit=1
ID: 73359
Updated by: stas@php.net
Reported by: me at michelgaschet dot gp
Summary: Bypass desactivated error reporting with
set_error_handler()
Status: Open
-Type: Security
+Type: Feature/Change Request
Package: PHP options/info functions
Operating System: All systems
PHP Version: 7.0.12
Block user comment: N
Private report: Y
New Comment:
If you can run code on the server, you don't have to do tricks with error handler - you can
output and in general do anything error handler does directly from your code.
Previous Comments:
------------------------------------------------------------------------
[2016-10-20 19:19:27] me at michelgaschet dot gp
Description:
------------
In a system with all error message unactivated for security reason (I.E Production server), it
remains possible to reactivate the error messages for a malicious user
having the ability to execute code although functions error_reporting()/ini_set() be disabled, with
the set_error_handler() is used.
Test script:
---------------
<?php
echo phpversion();
echo "<br />";
function myErrorHandler($errno, $errstr, $errfile, $errline) {
var_dump($errno);
var_dump($errstr);
var_dump($errfile);
var_dump($errline);
return true;
}
$old_error_handler = set_error_handler("myErrorHandler");
lolel;
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=73359&edit=1