Re: PHP deserialization techniques offer rich pickings for security researchers

From: Date: Wed, 17 Apr 2019 04:40:43 +0000
Subject: Re: PHP deserialization techniques offer rich pickings for security researchers
References: 1 2 3 4 5  Groups: php.internals 
Request: Send a blank email to internals+get-105301@lists.php.net to get a copy of this message
Hi! > This issue was discussed in this list before. > As long as PHP calls unserialize for phar metadata, object injection is > possible > which may allow malicious code execution. Right. That's why I want to make it not unserialize this data unless it's explicitly being requested. > I'm not sure if Phar metadata requires object or not. > If not, Phar may use JSON. Or we may add safer unserialize that ignores > object > and reference for maximum compatibility. That would break BC with all existing phars that use metadata. -- Stas Malyshev smalyshev@gmail.com

« previous php.internals (#105301) next »