Re: PHP deserialization techniques offer rich pickings for security researchers
| From: | Stanislav Malyshev | Date: | Mon, 15 Apr 2019 06:28:34 +0000 |
| Subject: | Re: PHP deserialization techniques offer rich pickings for security researchers | ||
| References: | 1 2 3 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-105276@lists.php.net to get a copy of this message | ||
Hi!
> Thanks for responding to this issue.
>
> Will calling getMetaData still parse and
> execute malicious code?
If it's contained in phar and serialized data and the surrounding code
(I understand that most techniques mentioned in the article rely on
certain vulnerable code being present) then yes.
--
Stas Malyshev
smalyshev@gmail.com