Disabling External Entities in libxml By Default
| From: | Anthony Ferrara | Date: | Wed, 29 Jul 2015 20:37:52 +0000 |
| Subject: | Disabling External Entities in libxml By Default | ||
| Groups: | php.internals | ||
| Request: | Send a blank email to internals+get-87372@lists.php.net to get a copy of this message | ||
All,
I wanted to float an idea by you for PHP 7 (or 7.1 depending on the
RM's feedback).
Currently, PHP by default is vulnerable to XXE attacks:
https://www.owasp.org/index.php/XML_External_Entity_(XXE)_Processing
To bypass this, you need to turn off external entity loading:
libxml_disable_entity_loader(true);
What I'm proposing is to disable entity loading by default. That way
it requires developers to opt-in to actually load external entities.
Thoughts?
Anthony