Re: Let's allow eval() to be turned off in PHP 8

From: Date: Tue, 26 Nov 2019 21:44:15 +0000
Subject: Re: Let's allow eval() to be turned off in PHP 8
References: 1 2 3  Groups: php.internals 
Request: Send a blank email to internals+get-107867@lists.php.net to get a copy of this message
> On Nov 26, 2019, at 11:27 AM, Ian Littman <iansltx@gmail.com> wrote: > > You're right that turning off eval() isn't a silver bullet, and if you can > get external code running on someone's box there are a lot worse things you > can do. > > On Tue, Nov 26, 2019 at 10:11 AM Benjamin Morel <benjamin.morel@gmail.com> > wrote: > >> Hi Ian, >> >> IMO, eval() is secure, as long as: >> >> - you’re not using it, or >> - you’re using it properly >> >> I’d say that as soon as your server has been compromised, eval() is the >> last of your worries, as pretty much anything becomes possible, including >> writing PHP code to a file and including/executing it. So I feel like >> disabling eval() will just make « hackers » have a good laugh There might be a good argument for turning it eval() and create_function() off by default for command-line use? #jmtcw -Mike

« previous php.internals (#107867) next »