Re: PHP deserialization techniques offer rich pickings for security researchers
| From: | Stanislav Malyshev | Date: | Wed, 17 Apr 2019 04:40:43 +0000 |
| Subject: | Re: PHP deserialization techniques offer rich pickings for security researchers | ||
| References: | 1 2 3 4 5 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-105301@lists.php.net to get a copy of this message | ||
Hi!
> This issue was discussed in this list before.
> As long as PHP calls unserialize for phar metadata, object injection is
> possible
> which may allow malicious code execution.
Right. That's why I want to make it not unserialize this data unless
it's explicitly being requested.
> I'm not sure if Phar metadata requires object or not.
> If not, Phar may use JSON. Or we may add safer unserialize that ignores
> object
> and reference for maximum compatibility.
That would break BC with all existing phars that use metadata.
--
Stas Malyshev
smalyshev@gmail.com