Re: Re: Bug 67072 resolution for 5.4/5.5
| From: | Marco Pivetta | Date: | Thu, 26 Jun 2014 01:07:18 +0000 |
| Subject: | Re: Re: Bug 67072 resolution for 5.4/5.5 | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-75084@lists.php.net to get a copy of this message | ||
On 26 June 2014 03:00, Stas Malyshev <smalyshev@sugarcrm.com> wrote:
> Hi!
>
> > You keep mentioning these two, but don't they assume that the serialized
> > data is user-provided?
>
> Yes, they do.
>
> > I don't think anybody sane would/should do that in first place, as it
>
> Simple search on github suggests otherwise.
>
*sane* doesn't mean everyone.
Allowing un-serializing data coming from user input is as bad as
eval(),
and trying to defend from it is also quite useless.
> > would be already possible to cause RCE just with any class implementing
> > the Serializable interface.
>
> Not sure how you could do that, could you please explain how would you
> cause that?
>
Assuming this exists in the user's codebase:
class Prank implements Serializable
{
public function serialize() {}
public function unserialize() { exec('rm -rf /'); }
}
Then send a serialized prank over the internets.
Other interesting security issues are related to this as well in my
opinion, but I'd have to do research on the problem first.
> I was, of course, speaking of running
> arbitrary code on C level, not just PHP methods purposed to handle the
> data by the developers.
>
That was my misunderstanding. Thanks for clarifying.
Marco Pivetta
http://twitter.com/Ocramius
http://ocramius.github.com/