Edit report at https://bugs.php.net/bug.php?id=73536&edit=1
ID: 73536
User updated by: peter dot mlich at volny dot cz
Reported by: peter dot mlich at volny dot cz
Summary: var_dump ignore private permitions in class
Status: Not a bug
Type: Feature/Change Request
Package: Unknown/Other Function
PHP Version: 5.6.28
Block user comment: N
Private report: N
New Comment:
example:
$path = '...';
$str = file_get_content($path);
$CFG = parseXYZ($str);
$my_class->setCfg($CFG);
unset($path);
unset($CFG);
var_dump($path);
You not know $path, if you not read this file. You can use file_get_content. But, i can use
fileReader.php, read from directory blocked by .htaccess for only read for only this file. I can
counting reading files in private variable. Readed cfg or not. You cannot use double times to read
one file.
Previous Comments:
------------------------------------------------------------------------
[2016-11-23 08:12:44] rasmus@php.net
A simple call to get_included_files() or a shell out to a grep will trivially get the file path.
------------------------------------------------------------------------
[2016-11-23 06:51:19] peter dot mlich at volny dot cz
Must know file path. But, if i open file do $tmp and rewrite to clas, unset($tmp), unset($CFG),
hacker no have information.
------------------------------------------------------------------------
[2016-11-20 15:45:38] rasmus@php.net
If a hacker has access to write arbitrary PHP on a site he can simply open up the file containing
the private properties and look at them. The access level of a property is not a security feature.
------------------------------------------------------------------------
[2016-11-20 08:02:17] peter dot mlich at volny dot cz
If it not bug, then lucky day for hackers. If i hide db name, psw dto class, hacker can easy show it
only with php command :)
I think, this is very stupid bug. I now need find new methode to hide password.
------------------------------------------------------------------------
[2016-11-16 10:08:43] stas@php.net
Thank you for taking the time to write to us, but this is not
a bug. Please double-check the documentation available at
http://www.php.net/manual/ and the instructions on how to
report
a bug at http://bugs.php.net/how-to-report.php
This is how var_dump is supposed to work. It's a debug function.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=73536
--
Edit this bug report at https://bugs.php.net/bug.php?id=73536&edit=1