Doc #55516 [Bgs]: is_callable can be a security vulnerability
| From: | stas@php.net | Date: | Fri, 26 Aug 2011 23:42:33 +0000 |
| Subject: | Doc #55516 [Bgs]: is_callable can be a security vulnerability | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-7068@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=55516&edit=1
ID: 55516
Updated by: stas@php.net
Reported by: thegreatall at gmail dot com
Summary: is_callable can be a security vulnerability
Status: Bogus
Type: Documentation Problem
Package: Documentation problem
Operating System: N/A
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
Also, you should use "$var instanceof Closure" in this case :)
Previous Comments:
------------------------------------------------------------------------
[2011-08-26 22:59:22] johannes@php.net
It is documented, that strings are callable types. We can't prevent all the ways a PHP
developer can shoot in his foot.
------------------------------------------------------------------------
[2011-08-26 22:25:09] thegreatall at gmail dot com
Description:
------------
If you would be writing a framework or any code that the developer can send a
parameter though and the receiving code uses is_callable() to test to see if the
variable is a lambda/closure type, they may be opening them selves up to a
security vulnerability if the attacker is able to set a string to that variable. I
recommend adding a note to that function's documentation saying that if you wish
to check to see if a variable is a lambda/closure use "is_a($var, 'Closure')". I
know this can be avoided by safe coding, but it can be a huge security issue.
Test script:
---------------
<?php
function buildGrid(array $data){
echo '<table>';
foreach($data as $key => $cell){
if(is_callable($cell)){ // This should be is_a($cell, 'Closure')
echo $cell($key);
}else{
echo '<tr><td>', htmlentities($key), '</td><td>',
htmlentities($cell), '</td></tr>';
}
}
echo '</table>';
}
$array = array(
'id' => $_REQUEST['id'],
'name' => $_REQUEST['name'],
'last_name' => $_REQUEST['last_name'],
function ($key){
return '<tr><td>A HEADER OR IMAGE OR SOMETHING THAT CANNOT BE EVALUATED OR
DISPLAYED UNLESS CALLED AT COMPILE TIME</td></tr>';
}
);
buildGrid($array);
/*
* If the attacker sent a request like:
'index.php?id=11111&name=somename&last_name=phpinfo'
* This will show this attacker all the phpinfo() for the server. This could be vary
* dangerious if the programmer had a function like showDebugInfo() as the user could possibly
* get very valuble info.
*/
?>
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=55516&edit=1