Req #62397 [Csd->ReO]: disable_functions = eval does not work
| From: | bukka@php.net | Date: | Fri, 09 Feb 2024 09:44:40 +0000 |
| Subject: | Req #62397 [Csd->ReO]: disable_functions = eval does not work | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-246436@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=62397&edit=1
ID: 62397
Updated by: bukka@php.net
Reported by: spamik at yum dot pl
Summary: disable_functions = eval does not work
-Status: Closed
+Status: Re-Opened
Type: Feature/Change Request
Package: *General Issues
PHP Version: 5.3.14
-Assigned To: krakjoe
+Assigned To:
Block user comment: N
Private report: N
New Comment:
Re-opening as single developer cannot make this decision. This needs to come from RFC and I believe
there are some good arguments for disabling eval.
Previous Comments:
------------------------------------------------------------------------
[2021-09-09 01:22:50] jake at qzdesign dot co dot uk
@krakjoe
> There is no difference between eval and include
This is not true. If malicious code were required to write a file to be
!included,
this could be monitored and potentially blocked by a separate tool running at the filesystem level.
> By the time a hacker has permission to execute unsafe code via eval or by any other means, it
> is too late.
Isn't that a bit like saying 2FA is pointless because by the time your password has been
cracked it's too late?
------------------------------------------------------------------------
[2019-06-03 09:30:54] krakjoe@php.net
There is no implementation of this that can provide any security.
There is no difference between eval and include, if a malicious hacker finds themselves on a system
where eval is disabled, they can just dump what they would eval and include it.
By the time a hacker has permission to execute unsafe code via eval or by any other means, it is too
late.
------------------------------------------------------------------------
[2019-06-03 09:24:07] petk@php.net
Re-opened bug and we're back at the beginning via above revert so when that will be more
properly fixed we can move forward here I guess.
------------------------------------------------------------------------
[2019-06-03 09:20:32] krakjoe@php.net
Automatic comment on behalf of krakjoe
Revision: http://git.php.net/?p=php-src.git;a=commit;h=ff96f25b12287de8105305b6f92c7714833066a7
Log: Revert "Fix bug #62397 - disable_functions does not work with eval."
------------------------------------------------------------------------
[2019-05-14 22:00:26] petk@php.net
Automatic comment on behalf of kontakt@beberlei.de
Revision: http://git.php.net/?p=php-src.git;a=commit;h=050d299364ded5cb7b878bc515aa763c9c623c4b
Log: Fix bug #62397 - disable_functions does not work with eval.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=62397
--
Edit this bug report at https://bugs.php.net/bug.php?id=62397&edit=1