Vulnerability by loading doctype-declaration of xml
| From: | Simon Schick | Date: | Wed, 29 Feb 2012 18:30:15 +0000 |
| Subject: | Vulnerability by loading doctype-declaration of xml | ||
| Groups: | php.internals | ||
| Request: | Send a blank email to internals+get-58341@lists.php.net to get a copy of this message | ||
Hi, all
I just read this post about a vulnerability by loading doctype-declaration
of an xml-string given in a request:
http://www.idontplaydarts.com/2011/02/scanning-the-internal-network-using-simplexml/
Would it be a good point to restrict which urls can be loaded in the
doctype, or is the following line the only possibility to prevent it in a
good way?
libxml_disable_entity_loader(true);
Bye
Simon