#49826 [Asn->Csd]: Code example known to be exploitable.
| From: | vrana@php.net | Date: | Fri, 13 Nov 2009 21:12:19 +0000 |
| Subject: | #49826 [Asn->Csd]: Code example known to be exploitable. | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-3134@lists.php.net to get a copy of this message | ||
ID: 49826
Updated by: vrana@php.net
Reported By: kore@php.net
-Status: Assigned
+Status: Closed
Bug Type: Documentation problem
Operating System: Irrelevant
PHP Version: Irrelevant
Assigned To: ilia
New Comment:
This bug has been fixed in the documentation's XML sources. Since the
online and downloadable versions of the documentation need some time
to get updated, we would like to ask you to be a bit patient.
Thank you for the report, and for helping us make our documentation
better.
Previous Comments:
------------------------------------------------------------------------
[2009-10-09 23:09:11] bjori@php.net
I think the argument about crashing php because it used recursive
function is a total crap.
There was a 'security fix' recently (the max_input_nesting_level INI
setting) to fix exactly that, and no Ilia was not the one who reported
it nor fixed it:
Added "max_input_nesting_level" php.ini option to limit
nesting level of input variables. Fix for MOPB-03-2007. (Stas).
And the code on the slide is worse AFAICT, it doesn't deal with arrays
nor $_REQUEST at all, so AFAICT it introduces security issues, not fixes
them.
Ilia: please have a look at the example and clarify if needed..
------------------------------------------------------------------------
[2009-10-09 21:18:15] kore@php.net
Description:
------------
Example #2 on
http://docs.php.net/manual/en/security.magicquotes.disabling.php
uses
source, which is known to be exploitable, like shown here:
http://ilia.ws/files/phpworks_security.pdf
(Slides 18 to 20)
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=49826&edit=1