Req #73536 [Nab]: var_dump ignore private permitions in class

From: Date: Thu, 24 Nov 2016 07:33:14 +0000
Subject: Req #73536 [Nab]: var_dump ignore private permitions in class
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-205594@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73536&edit=1

 ID:                 73536
 User updated by:    peter dot mlich at volny dot cz
 Reported by:        peter dot mlich at volny dot cz
 Summary:            var_dump ignore private permitions in class
 Status:             Not a bug
 Type:               Feature/Change Request
 Package:            Unknown/Other Function
 PHP Version:        5.6.28
 Block user comment: N
 Private report:     N

 New Comment:

example:

$path = '...';
$str = file_get_content($path);
$CFG = parseXYZ($str);
$my_class->setCfg($CFG);
unset($path);
unset($CFG);
var_dump($path);

You not know $path, if you not read this file. You can use file_get_content. But, i can use
fileReader.php, read from directory blocked by .htaccess for only read for only this file. I can
counting reading files in private variable. Readed cfg or not. You cannot use double times to read
one file.


Previous Comments:
------------------------------------------------------------------------
[2016-11-23 08:12:44] rasmus@php.net

A simple call to get_included_files() or a shell out to a grep will trivially get the file path.

------------------------------------------------------------------------
[2016-11-23 06:51:19] peter dot mlich at volny dot cz

Must know file path. But, if i open file do $tmp and rewrite to clas, unset($tmp), unset($CFG),
hacker no have information.

------------------------------------------------------------------------
[2016-11-20 15:45:38] rasmus@php.net

If a hacker has access to write arbitrary PHP on a site he can simply open up the file containing
the private properties and look at them. The access level of a property is not a security feature.

------------------------------------------------------------------------
[2016-11-20 08:02:17] peter dot mlich at volny dot cz

If it not bug, then lucky day for hackers. If i hide db name, psw dto class, hacker can easy show it
only with php command :)
I think, this is very stupid bug. I now need find new methode to hide password.

------------------------------------------------------------------------
[2016-11-16 10:08:43] stas@php.net

Thank you for taking the time to write to us, but this is not
a bug. Please double-check the documentation available at
http://www.php.net/manual/ and the instructions on how to
report
a bug at http://bugs.php.net/how-to-report.php

This is how var_dump is supposed to work. It's a debug function.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=73536


--
Edit this bug report at https://bugs.php.net/bug.php?id=73536&edit=1


Thread (1 message)

  • peter dot mlich at volny dot cz
  • Unknown Message
    • peter dot mlich at volny dot cz
« previous php.bugs (#205594) next »