Re: How does the PHP Ghost one-liner work
| From: | Patrick Schaaf | Date: | Fri, 30 Jan 2015 19:17:55 +0000 |
| Subject: | Re: How does the PHP Ghost one-liner work | ||
| Groups: | php.internals | ||
| Request: | Send a blank email to internals+get-81448@lists.php.net to get a copy of this message | ||
Am 30.01.2015 20:09 schrieb "Leigh" <leight@gmail.com>:
>
> Well, I guess in theory we should be limiting the size of input to
> gethostbyname to 255 characters.
Yeah, but in theory the C library gethostbyname() should do the same...
There will be a lot of things that could be checked up-front instead of
relying on the C layer stuff to do its work. Do you want to pre-examine
pathnames regarding maximum path name lengths? Check the fopen mode
parameter for posixly valid content? There's a zillion ways libc might be
vulnerable. And any such up-front in PHP check might then be blessed with
exploitable bugs itself...
best regards
Patrick