Bug #81153 [Dup]: bypass __wakeup
| From: | j7ur8 at qq dot com | Date: | Thu, 17 Jun 2021 09:00:45 +0000 |
| Subject: | Bug #81153 [Dup]: bypass __wakeup | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-234451@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=81153&edit=1
ID: 81153
User updated by: j7ur8 at qq dot com
Reported by: j7ur8 at qq dot com
Summary: bypass __wakeup
Status: Duplicate
Type: Bug
Package: Class/Object related
Operating System: ALL
PHP Version: 7.3.28
Block user comment: N
Private report: N
New Comment:
this is another one!
Previous Comments:
------------------------------------------------------------------------
[2021-06-17 08:59:51] requinix@php.net
You already reported this.
------------------------------------------------------------------------
[2021-06-17 08:49:21] j7ur8 at qq dot com
Description:
------------
bad unserialize string makes __wakeup ineffective.
Success:
7.0.15 - 7.0.33, 7.1.1 - 7.1.33, 7.2.0 - 7.2.34, 7.3.0 - 7.3.28, 7.4.0 - 7.4.16, 8.0.0 - 8.0.3
Fail:
5.0.0 - 5.0.5, 5.1.0 - 5.1.6, 5.2.0 - 5.2.17, 5.3.0 - 5.3.29, 5.4.0 - 5.4.45, 5.5.0 - 5.5.38,
5.6.0 - 5.6.40, 7.0.0 - 7.0.14, 7.1.0
Test script:
---------------
// https://3v4l.org/4nZUm
<?php
class D{
public $flag=True;
public function __get($a){
if($this->flag){
echo 'flag';
}else{
echo 'hint';
}
}
public function __wakeup(){
$this->flag = False;
}
}
class C{
public function __destruct(){
echo $this->c->b;
}
}
@unserialize('O:1:"C":1:{s:1:"c";O:1:"D":0:{};N;}');
Expected result:
----------------
hint
Actual result:
--------------
flag
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=81153&edit=1