Req #62397 [ReO->Csd]: disable_functions = eval does not work

From: Date: Tue, 14 May 2019 22:00:26 +0000
Subject: Req #62397 [ReO->Csd]: disable_functions = eval does not work
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-220853@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=62397&edit=1

 ID:                 62397
 Updated by:         petk@php.net
 Reported by:        spamik at yum dot pl
 Summary:            disable_functions = eval does not work
-Status:             Re-Opened
+Status:             Closed
 Type:               Feature/Change Request
 Package:            *General Issues
 PHP Version:        5.3.14
 Block user comment: N
 Private report:     N

 New Comment:

Automatic comment on behalf of kontakt@beberlei.de
Revision: http://git.php.net/?p=php-src.git;a=commit;h=050d299364ded5cb7b878bc515aa763c9c623c4b
Log: Fix bug #62397 - disable_functions does not work with eval.


Previous Comments:
------------------------------------------------------------------------
[2019-04-28 15:57:31] beberlei@php.net

The following pull request has been associated:

Patch Name: Fix bug #62397 - disable_functions does not work with eval.
On GitHub:  https://github.com/php/php-src/pull/4084
Patch:      https://github.com/php/php-src/pull/4084.patch

------------------------------------------------------------------------
[2015-03-24 12:12:41] phpbugs at notmyaddie dot com

Considering how prolific the use of eval() is in malicious code I cannot believe it can't be
turned off without installing something like suhosin. Arguing what it is is beside the point. It is
a gaping hole in the security and stability of php servers that cannot be closed without 3'rd
party software.

"If eval() is the answer, you're almost certainly asking the
wrong question. -- Rasmus Lerdorf, BDFL of PHP"

And if you're going to argue that a function is not evil and should not be used for evil
things, tell that to all the 'hackers' using it. I want to install a gate at my door by
turning this off. Telling me I can't because I should not break into my own house is pointless

------------------------------------------------------------------------
[2012-06-29 16:31:07] isee at a dot troll

@anon: pretty sure you just got trolled

------------------------------------------------------------------------
[2012-06-28 17:37:40] anon at anon dot anon

@e756937

(1) haven't you heard of include()?
(2) $_GET['path'] not validated
(3) no apparent rhyme or reason to mix of single and double quoting
(4) echo parameter neither quoted nor escaped
(5) echo within eval?
(6) why do you need eval for that at all?
(7) "I also use it for user auth" -- I completely doubt you need to.
(8) exec() is unrelated.
(9) The mere existence of an easy way to disable eval does not mean your host will do that. Your
host can already disable it if they want to. Hosts often let you specify a custom php.ini or other
configuration anyway, and this is certainly true on a server plan that serves 10k daily uniques for
you.
(10) Using a 10minutemail.com address with a commenting system that doesn't verify the email.

Conclusion => magic_quotes level of IQ

------------------------------------------------------------------------
[2012-06-26 17:59:39] e756937 at rtrtr dot com

I run a website with 10k uniques per day and eval() is CRUCIAL to my business

example:
$page = file_get_contents($_GET['path'].".php");
eval("echo ".$page.";");

I also use it for user auth and access to exec() since my host blocks it

As you can see, eval() is a very good thing to use and I don't want it gone, kk??

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=62397


--
Edit this bug report at https://bugs.php.net/bug.php?id=62397&edit=1


Thread (22 messages)

« previous php.bugs (#220853) next »