Sec Bug->Bug #81151 [Opn]: bypass __wakeup

From: Date: Thu, 17 Jun 2021 05:24:35 +0000
Subject: Sec Bug->Bug #81151 [Opn]: bypass __wakeup
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-234444@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81151&edit=1 ID: 81151 Updated by: stas@php.net Reported by: j7ur8 at qq dot com Summary: bypass __wakeup Status: Open -Type: Security +Type: Bug Package: Class/Object related Operating System: All PHP Version: 7.3.28 Block user comment: N Private report: Y New Comment: __wakeup is not a security feature, so it's not a security issue. Previous Comments: ------------------------------------------------------------------------ [2021-06-17 05:21:55] j7ur8 at qq dot com Description: ------------ use C: to bypass __wakeup. Test script: --------------- // https://3v4l.org/YAje0 <?php class E { public function __construct(){ } public function __destruct(){ echo "destruct"; } public function __wakeup(){ echo "wake up"; } } var_dump(unserialize('C:1:"E":0:{}')); Expected result: ---------------- For class E don't implements Serializable, maybe unserialize should return an Error. Actual result: -------------- Warning: Class E has no unserializer in /in/YAje0 on line 17 object(E)#1 (0) { } destruct /* In my understand, "C:" means a class implements Serializable, and it don't suport __wakeup. At here, class E doesn't implements Serializable, and __wakeup ineffective, __destruct works. Should it be? i don't know. */ ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=81151&edit=1

« previous php.bugs (#234444) next »