Re: Let's allow eval() to be turned off in PHP 8
| From: | Mike Schinkel | Date: | Tue, 26 Nov 2019 21:44:15 +0000 |
| Subject: | Re: Let's allow eval() to be turned off in PHP 8 | ||
| References: | 1 2 3 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-107867@lists.php.net to get a copy of this message | ||
> On Nov 26, 2019, at 11:27 AM, Ian Littman <iansltx@gmail.com> wrote:
>
> You're right that turning off eval() isn't a silver bullet, and if you can
> get external code running on someone's box there are a lot worse things you
> can do.
>
> On Tue, Nov 26, 2019 at 10:11 AM Benjamin Morel <benjamin.morel@gmail.com>
> wrote:
>
>> Hi Ian,
>>
>> IMO, eval() is secure, as long as:
>>
>> - you’re not using it, or
>> - you’re using it properly
>>
>> I’d say that as soon as your server has been compromised, eval() is the
>> last of your worries, as pretty much anything becomes possible, including
>> writing PHP code to a file and including/executing it. So I feel like
>> disabling eval() will just make « hackers » have a good laugh
There might be a good argument for turning it eval() and create_function() off by default for
command-line use?
#jmtcw
-Mike