Req #62397 [ReO->Csd]: disable_functions = eval does not work

From: Date: Mon, 03 Jun 2019 09:30:54 +0000
Subject: Req #62397 [ReO->Csd]: disable_functions = eval does not work
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-221091@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=62397&edit=1 ID: 62397 Updated by: krakjoe@php.net Reported by: spamik at yum dot pl Summary: disable_functions = eval does not work -Status: Re-Opened +Status: Closed Type: Feature/Change Request Package: *General Issues PHP Version: 5.3.14 -Assigned To: +Assigned To: krakjoe Block user comment: N Private report: N New Comment: There is no implementation of this that can provide any security. There is no difference between eval and include, if a malicious hacker finds themselves on a system where eval is disabled, they can just dump what they would eval and include it. By the time a hacker has permission to execute unsafe code via eval or by any other means, it is too late. Previous Comments: ------------------------------------------------------------------------ [2019-06-03 09:24:07] petk@php.net Re-opened bug and we're back at the beginning via above revert so when that will be more properly fixed we can move forward here I guess. ------------------------------------------------------------------------ [2019-06-03 09:20:32] krakjoe@php.net Automatic comment on behalf of krakjoe Revision: http://git.php.net/?p=php-src.git;a=commit;h=ff96f25b12287de8105305b6f92c7714833066a7 Log: Revert "Fix bug #62397 - disable_functions does not work with eval." ------------------------------------------------------------------------ [2019-05-14 22:00:26] petk@php.net Automatic comment on behalf of kontakt@beberlei.de Revision: http://git.php.net/?p=php-src.git;a=commit;h=050d299364ded5cb7b878bc515aa763c9c623c4b Log: Fix bug #62397 - disable_functions does not work with eval. ------------------------------------------------------------------------ [2019-04-28 15:57:31] beberlei@php.net The following pull request has been associated: Patch Name: Fix bug #62397 - disable_functions does not work with eval. On GitHub: https://github.com/php/php-src/pull/4084 Patch: https://github.com/php/php-src/pull/4084.patch ------------------------------------------------------------------------ [2015-03-24 12:12:41] phpbugs at notmyaddie dot com Considering how prolific the use of eval() is in malicious code I cannot believe it can't be turned off without installing something like suhosin. Arguing what it is is beside the point. It is a gaping hole in the security and stability of php servers that cannot be closed without 3'rd party software. "If eval() is the answer, you're almost certainly asking the wrong question. -- Rasmus Lerdorf, BDFL of PHP" And if you're going to argue that a function is not evil and should not be used for evil things, tell that to all the 'hackers' using it. I want to install a gate at my door by turning this off. Telling me I can't because I should not break into my own house is pointless ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=62397 -- Edit this bug report at https://bugs.php.net/bug.php?id=62397&edit=1

« previous php.bugs (#221091) next »