Edit report at https://bugs.php.net/bug.php?id=62397&edit=1
ID: 62397
Updated by: krakjoe@php.net
Reported by: spamik at yum dot pl
Summary: disable_functions = eval does not work
-Status: Re-Opened
+Status: Closed
Type: Feature/Change Request
Package: *General Issues
PHP Version: 5.3.14
-Assigned To:
+Assigned To: krakjoe
Block user comment: N
Private report: N
New Comment:
There is no implementation of this that can provide any security.
There is no difference between eval and include, if a malicious hacker finds themselves on a system
where eval is disabled, they can just dump what they would eval and include it.
By the time a hacker has permission to execute unsafe code via eval or by any other means, it is too
late.
Previous Comments:
------------------------------------------------------------------------
[2019-06-03 09:24:07] petk@php.net
Re-opened bug and we're back at the beginning via above revert so when that will be more
properly fixed we can move forward here I guess.
------------------------------------------------------------------------
[2019-06-03 09:20:32] krakjoe@php.net
Automatic comment on behalf of krakjoe
Revision: http://git.php.net/?p=php-src.git;a=commit;h=ff96f25b12287de8105305b6f92c7714833066a7
Log: Revert "Fix bug #62397 - disable_functions does not work with eval."
------------------------------------------------------------------------
[2019-05-14 22:00:26] petk@php.net
Automatic comment on behalf of kontakt@beberlei.de
Revision: http://git.php.net/?p=php-src.git;a=commit;h=050d299364ded5cb7b878bc515aa763c9c623c4b
Log: Fix bug #62397 - disable_functions does not work with eval.
------------------------------------------------------------------------
[2019-04-28 15:57:31] beberlei@php.net
The following pull request has been associated:
Patch Name: Fix bug #62397 - disable_functions does not work with eval.
On GitHub: https://github.com/php/php-src/pull/4084
Patch: https://github.com/php/php-src/pull/4084.patch
------------------------------------------------------------------------
[2015-03-24 12:12:41] phpbugs at notmyaddie dot com
Considering how prolific the use of eval() is in malicious code I cannot believe it can't be
turned off without installing something like suhosin. Arguing what it is is beside the point. It is
a gaping hole in the security and stability of php servers that cannot be closed without 3'rd
party software.
"If eval() is the answer, you're almost certainly asking the
wrong question. -- Rasmus Lerdorf, BDFL of PHP"
And if you're going to argue that a function is not evil and should not be used for evil
things, tell that to all the 'hackers' using it. I want to install a gate at my door by
turning this off. Telling me I can't because I should not break into my own house is pointless
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=62397
--
Edit this bug report at https://bugs.php.net/bug.php?id=62397&edit=1