Re: Overwriting (internal) functions
| From: | Wico de Leeuw | Date: | Fri, 25 Aug 2000 14:17:19 +0000 |
| Subject: | Re: Overwriting (internal) functions | ||
| References: | 1 2 3 4 5 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-30645@lists.php.net to get a copy of this message | ||
At 08:43 25-8-00 -0500, Andrei Zmievski wrote:
On Fri, 25 Aug 2000, Wico de Leeuw wrote: Maybe with a special function wich only exsist when not in safemode and the replacement would be only in the current script. Maybe it's safe enough then? btw at what kinda security vulnerabilities. where you thinking? Imagine a user downloads a library that seems fairly benign, but it replaces the default mail() function with another one that secretly collects users's computer's data and emails it to the library author and then emulates normal functionality of mail(). This will be even worse when people start downloading compiled libraries without access to source code.hmmm You got a point there, but whould be nice though Maybe a special Function you gotta call first on a page to allow the page to use overwritten function(s) And a option in php.ini to allow it on all pages (default off ofcourse) And with compiled liberies you keep the problem that you don't know what it will do I can register an shutdown function (or even when you include it can do things)wich collects some stuff and still emails it to the author (user and password for the current dir if not empty) you will never notice it Wico
-Andrei "I think it would be a good idea." -- Mahatma Gandhi, when asked what he thought of Western civilization...