Re: Let's allow eval() to be turned off in PHP 8

From: Date: Tue, 26 Nov 2019 21:54:49 +0000
Subject: Re: Let's allow eval() to be turned off in PHP 8
References: 1 2 3 4  Groups: php.internals 
Request: Send a blank email to internals+get-107868@lists.php.net to get a copy of this message
create_function() will be gone as of PHP 8 anyway. For eval(), e.g. psysh uses it (and, as a result, e.g. Laravel Tinker). So defaulting eval to disabled doesn't seem tenable. Not what I'm asking anyway...I just want the *ability* to turn it off (likely only in apache/fpm configs actually, leaving it on for the CLI). On Tue, Nov 26, 2019 at 3:44 PM Mike Schinkel <mike@newclarity.net> wrote: > On Nov 26, 2019, at 11:27 AM, Ian Littman <iansltx@gmail.com> wrote: > > > You're right that turning off eval() isn't a silver bullet, and if you can > get external code running on someone's box there are a lot worse things you > can do. > > On Tue, Nov 26, 2019 at 10:11 AM Benjamin Morel <benjamin.morel@gmail.com> > wrote: > > Hi Ian, > > IMO, eval() is secure, as long as: > > - you’re not using it, or > - you’re using it properly > > I’d say that as soon as your server has been compromised, eval() is the > last of your worries, as pretty much anything becomes possible, including > writing PHP code to a file and including/executing it. So I feel like > disabling eval() will just make « hackers » have a good laugh > > > > There *might* be a good argument for turning it eval() and > create_function() off by default for command-line use? > > #jmtcw > > -Mike > >

« previous php.internals (#107868) next »