Sec Bug->Bug #81151 [Opn]: bypass __wakeup
| From: | stas@php.net | Date: | Thu, 17 Jun 2021 05:24:35 +0000 |
| Subject: | Sec Bug->Bug #81151 [Opn]: bypass __wakeup | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-234444@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=81151&edit=1
ID: 81151
Updated by: stas@php.net
Reported by: j7ur8 at qq dot com
Summary: bypass __wakeup
Status: Open
-Type: Security
+Type: Bug
Package: Class/Object related
Operating System: All
PHP Version: 7.3.28
Block user comment: N
Private report: Y
New Comment:
__wakeup is not a security feature, so it's not a security issue.
Previous Comments:
------------------------------------------------------------------------
[2021-06-17 05:21:55] j7ur8 at qq dot com
Description:
------------
use
C: to bypass __wakeup.
Test script:
---------------
// https://3v4l.org/YAje0
<?php
class E {
public function __construct(){
}
public function __destruct(){
echo "destruct";
}
public function __wakeup(){
echo "wake up";
}
}
var_dump(unserialize('C:1:"E":0:{}'));
Expected result:
----------------
For class E don't implements Serializable, maybe unserialize should return an
Error.
Actual result:
--------------
Warning: Class E has no unserializer in /in/YAje0 on line 17
object(E)#1 (0) {
}
destruct
/*
In my understand, "C:" means a class implements Serializable, and it don't suport
__wakeup. At here, class E doesn't implements Serializable, and __wakeup ineffective,
__destruct works. Should it be? i don't know.
*/
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=81151&edit=1