Re: Re: Bug 67072 resolution for 5.4/5.5

From: Date: Thu, 26 Jun 2014 01:07:18 +0000
Subject: Re: Re: Bug 67072 resolution for 5.4/5.5
References: 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19  Groups: php.internals 
Request: Send a blank email to internals+get-75084@lists.php.net to get a copy of this message
On 26 June 2014 03:00, Stas Malyshev <smalyshev@sugarcrm.com> wrote: > Hi! > > > You keep mentioning these two, but don't they assume that the serialized > > data is user-provided? > > Yes, they do. > > > I don't think anybody sane would/should do that in first place, as it > > Simple search on github suggests otherwise. > *sane* doesn't mean everyone. Allowing un-serializing data coming from user input is as bad as eval(), and trying to defend from it is also quite useless. > > would be already possible to cause RCE just with any class implementing > > the Serializable interface. > > Not sure how you could do that, could you please explain how would you > cause that? > Assuming this exists in the user's codebase: class Prank implements Serializable { public function serialize() {} public function unserialize() { exec('rm -rf /'); } } Then send a serialized prank over the internets. Other interesting security issues are related to this as well in my opinion, but I'd have to do research on the problem first. > I was, of course, speaking of running > arbitrary code on C level, not just PHP methods purposed to handle the > data by the developers. > That was my misunderstanding. Thanks for clarifying. Marco Pivetta http://twitter.com/Ocramius http://ocramius.github.com/

« previous php.internals (#75084) next »