Req #62397 [Csd->ReO]: disable_functions = eval does not work

From: Date: Fri, 09 Feb 2024 09:44:40 +0000
Subject: Req #62397 [Csd->ReO]: disable_functions = eval does not work
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-246436@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=62397&edit=1 ID: 62397 Updated by: bukka@php.net Reported by: spamik at yum dot pl Summary: disable_functions = eval does not work -Status: Closed +Status: Re-Opened Type: Feature/Change Request Package: *General Issues PHP Version: 5.3.14 -Assigned To: krakjoe +Assigned To: Block user comment: N Private report: N New Comment: Re-opening as single developer cannot make this decision. This needs to come from RFC and I believe there are some good arguments for disabling eval. Previous Comments: ------------------------------------------------------------------------ [2021-09-09 01:22:50] jake at qzdesign dot co dot uk @krakjoe > There is no difference between eval and include This is not true. If malicious code were required to write a file to be !included, this could be monitored and potentially blocked by a separate tool running at the filesystem level. > By the time a hacker has permission to execute unsafe code via eval or by any other means, it > is too late. Isn't that a bit like saying 2FA is pointless because by the time your password has been cracked it's too late? ------------------------------------------------------------------------ [2019-06-03 09:30:54] krakjoe@php.net There is no implementation of this that can provide any security. There is no difference between eval and include, if a malicious hacker finds themselves on a system where eval is disabled, they can just dump what they would eval and include it. By the time a hacker has permission to execute unsafe code via eval or by any other means, it is too late. ------------------------------------------------------------------------ [2019-06-03 09:24:07] petk@php.net Re-opened bug and we're back at the beginning via above revert so when that will be more properly fixed we can move forward here I guess. ------------------------------------------------------------------------ [2019-06-03 09:20:32] krakjoe@php.net Automatic comment on behalf of krakjoe Revision: http://git.php.net/?p=php-src.git;a=commit;h=ff96f25b12287de8105305b6f92c7714833066a7 Log: Revert "Fix bug #62397 - disable_functions does not work with eval." ------------------------------------------------------------------------ [2019-05-14 22:00:26] petk@php.net Automatic comment on behalf of kontakt@beberlei.de Revision: http://git.php.net/?p=php-src.git;a=commit;h=050d299364ded5cb7b878bc515aa763c9c623c4b Log: Fix bug #62397 - disable_functions does not work with eval. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=62397 -- Edit this bug report at https://bugs.php.net/bug.php?id=62397&edit=1

« previous php.bugs (#246436) next »