Re: Overwriting (internal) functions
| From: | Andrei Zmievski | Date: | Fri, 25 Aug 2000 13:43:28 +0000 |
| Subject: | Re: Overwriting (internal) functions | ||
| References: | 1 2 3 4 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-30642@lists.php.net to get a copy of this message | ||
On Fri, 25 Aug 2000, Wico de Leeuw wrote:
> Maybe with a special function wich only exsist when not in safemode and the
> replacement would be only in the current script.
>
> Maybe it's safe enough then?
>
> btw at what kinda security vulnerabilities. where you thinking?
Imagine a user downloads a library that seems fairly benign, but it
replaces the default mail() function with another one that secretly
collects users's computer's data and emails it to the library author
and then emulates normal functionality of mail(). This will be even
worse when people start downloading compiled libraries without access to
source code.
-Andrei
"I think it would be a good idea." -- Mahatma Gandhi,
when asked what he thought of Western civilization...