#49826 [Opn->Asn]: Code example known to be exploitable.

From: Date: Fri, 09 Oct 2009 23:09:11 +0000
Subject: #49826 [Opn->Asn]: Code example known to be exploitable.
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-2916@lists.php.net to get a copy of this message
ID: 49826 Updated by: bjori@php.net Reported By: kore@php.net -Status: Open +Status: Assigned Bug Type: Documentation problem Operating System: Irrelevant PHP Version: Irrelevant -Assigned To: +Assigned To: ilia New Comment: I think the argument about crashing php because it used recursive function is a total crap. There was a 'security fix' recently (the max_input_nesting_level INI setting) to fix exactly that, and no Ilia was not the one who reported it nor fixed it: Added "max_input_nesting_level" php.ini option to limit nesting level of input variables. Fix for MOPB-03-2007. (Stas). And the code on the slide is worse AFAICT, it doesn't deal with arrays nor $_REQUEST at all, so AFAICT it introduces security issues, not fixes them. Ilia: please have a look at the example and clarify if needed.. Previous Comments: ------------------------------------------------------------------------ [2009-10-09 21:18:15] kore@php.net Description: ------------ Example #2 on http://docs.php.net/manual/en/security.magicquotes.disabling.php uses source, which is known to be exploitable, like shown here: http://ilia.ws/files/phpworks_security.pdf (Slides 18 to 20) ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=49826&edit=1

« previous php.doc.bugs (#2916) next »