Bug #74860 [Com]: Uncaught exceptions not being formatted properly when error_log set to "syslog"
| From: | spam2 at rhsoft dot net | Date: | Mon, 07 Aug 2017 05:01:27 +0000 |
| Subject: | Bug #74860 [Com]: Uncaught exceptions not being formatted properly when error_log set to "syslog" | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-210544@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=74860&edit=1
ID: 74860
Comment by: spam2 at rhsoft dot net
Reported by: philipp at redfish-solutions dot com
Summary: Uncaught exceptions not being formatted properly
when error_log set to "syslog"
Status: Open
Type: Bug
Package: Output Control
Operating System: linux 4.9.30
PHP Version: 7.1.6
Block user comment: N
Private report: N
New Comment:
what is your problem? i just pointed out that control chars has to be filtered at a central point so
that this affects syslog(), error_log(), trigger_error() and what not which leads in producing
logfiles - not more and not less - dunno why you needed to make dumb answers like "why would
anyone execute logfiles" and argue around at all
currently it just sucks that you need to filter logoutput in userland and in case of trigger_error
have no way to don't break the html page by not use htmlentities() while at the same time they
appear in the logfiles where nobody beeds them
so what is my point? that currently the whole error handling / logging is a complete mess
Previous Comments:
------------------------------------------------------------------------
[2017-08-07 03:57:26] philipp at redfish-solutions dot com
> yes, by simply sanitize *everything* passed to whatever function if it can contain untrusted
> input and log output *clearly* falls in that scope
You said to fix php_syslog(). I pointed out that this was a #define to syslog().
I *am* fixing the way we call syslog.
Perhaps look at the patch first before telling me how it falls short.
------------------------------------------------------------------------
[2017-08-05 03:59:55] spam2 at rhsoft dot net
> So how would I fix that?
by simply sanitize the arguments passed to external libraries
> There's a limited amount of bandwidth to secure systems,
> and you need to expend your energy and resources wisely
yes, by< simply sanitize *everything* passed to whatever function if it can contain untrusted
input and log output *clearly* falls in that scope
------------------------------------------------------------------------
[2017-08-05 00:02:28] philipp at redfish-solutions dot com
> THAT IS HOW SECURITY WORKS and not by a sloppy "there should not happen something
> bad" idiot attitude
It's not sloppy. It's realistic.
I've literally fixed thousands of potential exploits in my lifetime. At one point, I was doing
it full-time.
There's a limited amount of bandwidth to secure systems, and you need to expend your energy and
resources wisely.
There are an infinite number of files which could theoretically have control characters dumped into
them via an equally infinite number of vectors.
They can't all be fixed.
What can be fixed is the singular vulnerability in Xterm.
You also can't put a bandaid over the symptom while calling the cause simultaneously fixed.
That's not security. That self-delusion.
------------------------------------------------------------------------
[2017-08-04 22:05:03] philipp at redfish-solutions dot com
> The fix is in the wrong place. The fix should be to modify the php_syslog function to conform
> with expectations. I believe a more robust fix would be preferable ...
You know that there is no actual function called php_syslog(), right? And that it's a macro
which either points to std_syslog() or else to syslog() directly. And both of those are in external
libraries. So how would I fix that?
------------------------------------------------------------------------
[2017-08-04 21:58:34] spam2 at rhsoft dot net
GDAMNED:it does not matter where the vulnerability is - make sure that f***g Logfiles don't
contain control chars at all - THAT IS HOW SECURITY WORKS and not by a sloppy "there should not
happen something bad" idiot attitude
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=74860
--
Edit this bug report at https://bugs.php.net/bug.php?id=74860&edit=1