Re: Disabling External Entities in libxml By Default

From: Date: Wed, 29 Jul 2015 22:01:59 +0000
Subject: Re: Disabling External Entities in libxml By Default
References: 1  Groups: php.internals 
Request: Send a blank email to internals+get-87377@lists.php.net to get a copy of this message
Hi! > Currently, PHP by default is vulnerable to XXE attacks: > > https://www.owasp.org/index.php/XML_External_Entity_(XXE)_Processing > > To bypass this, you need to turn off external entity loading: > > libxml_disable_entity_loader(true); AFAIR right now, due to how it is implemented, this blocks loading XML content from files with something like XMLReader::open() - due to the use of the same code path by both. It may have changes since last time I looked, but it definitely was a major reason why default stayed that way. What people did is something like that: libxml_disable_entity_loader( false ); $reader->open( $filename ); libxml_disable_entity_loader( true ); I imagine we could do better. But we need to be careful - if we just set it as disabled, we could break a lot of unsuspecting apps that do nothing more that reading XML files. -- Stas Malyshev smalyshev@gmail.com

« previous php.internals (#87377) next »