Re: Let's allow eval() to be turned off in PHP 8
| From: | Stanislav Malyshev | Date: | Tue, 26 Nov 2019 22:21:30 +0000 |
| Subject: | Re: Let's allow eval() to be turned off in PHP 8 | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-107869@lists.php.net to get a copy of this message | ||
Hi!
> Let's just say that eval() and create_function() are the cornerstone of
> PHP-based exploit toolkits. Yes, if the hackers get in there are other
> problems with your codebase, but as a defense in depth measure most
> applications need neither create_function() nor the eval() language
> construct, so they might as well be disabled.
I get defense in depth, but I don't understand what it means in this
case. Since you're talking about disabling functions, I assume we're
talking about the situation where there's code execution access. From
that point, you can execute any code. What is the value of disabling
eval() here? You don't need eval, you can run any code you want
directly! Am I missing something here?
--
Stas Malyshev
smalyshev@gmail.com