#49826 [Asn->Csd]: Code example known to be exploitable.

From: Date: Fri, 13 Nov 2009 21:12:19 +0000
Subject: #49826 [Asn->Csd]: Code example known to be exploitable.
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-3134@lists.php.net to get a copy of this message
ID: 49826 Updated by: vrana@php.net Reported By: kore@php.net -Status: Assigned +Status: Closed Bug Type: Documentation problem Operating System: Irrelevant PHP Version: Irrelevant Assigned To: ilia New Comment: This bug has been fixed in the documentation's XML sources. Since the online and downloadable versions of the documentation need some time to get updated, we would like to ask you to be a bit patient. Thank you for the report, and for helping us make our documentation better. Previous Comments: ------------------------------------------------------------------------ [2009-10-09 23:09:11] bjori@php.net I think the argument about crashing php because it used recursive function is a total crap. There was a 'security fix' recently (the max_input_nesting_level INI setting) to fix exactly that, and no Ilia was not the one who reported it nor fixed it: Added "max_input_nesting_level" php.ini option to limit nesting level of input variables. Fix for MOPB-03-2007. (Stas). And the code on the slide is worse AFAICT, it doesn't deal with arrays nor $_REQUEST at all, so AFAICT it introduces security issues, not fixes them. Ilia: please have a look at the example and clarify if needed.. ------------------------------------------------------------------------ [2009-10-09 21:18:15] kore@php.net Description: ------------ Example #2 on http://docs.php.net/manual/en/security.magicquotes.disabling.php uses source, which is known to be exploitable, like shown here: http://ilia.ws/files/phpworks_security.pdf (Slides 18 to 20) ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=49826&edit=1

« previous php.doc.bugs (#3134) next »