Re: [Concept] Flip relative function lookup order (global, then local)

From: Date: Thu, 22 Aug 2024 08:09:52 +0000
Subject: Re: [Concept] Flip relative function lookup order (global, then local)
References: 1 2  Groups: php.internals 
Request: Send a blank email to internals+get-125096@lists.php.net to get a copy of this message
On Wed, Aug 21, 2024, at 20:32, John Coggeshall wrote: > > > On Aug 21 2024, at 2:10 pm, Ilija Tovilo <tovilo.ilija@gmail.com> wrote: >> >> Including a malicious composer package already allows for arbitrary >> code execution, do you really need more than that? > > Of course. We've seen many examples in the wild of 3rd party libraries getting hijacked to > inject malicious code (e.g. the whole xz attack).. This behavior in > PHP is not obvious, and provides a way to covertly target and hijack specific highly sensitive > functions without an obvious way to detect it -- while otherwise behaving exactly as a developer > would expect. > > Why possibly would we want to make it easier to perform such an attack, which as Illija pointed > out is actually making PHP slower, in the name of backward compatibility? Defense in depth is a > cornerstone of application security. > > John If you have the ability to inject arbitrary code, you've already lost. It doesn't matter whether they use this feature, or just register a shutdown function, autoloader, replace classes/functions/methods entirely, or whatever. Should we remove those features as well? — Rob

« previous php.internals (#125096) next »