Re: Disabling External Entities in libxml By Default
| From: | Rowan Collins | Date: | Thu, 30 Jul 2015 21:46:59 +0000 |
| Subject: | Re: Disabling External Entities in libxml By Default | ||
| References: | 1 2 3 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-87421@lists.php.net to get a copy of this message | ||
On 30 July 2015 19:25:47 BST, Anthony Ferrara <ircmaxell@gmail.com> wrote:
> I thought SOAP was dead already.
Tell that to the "Enterprises" who drag and drop in Visual Studio to create useless
wrappers around hand-written XML because that's their definition of "web service". :P
I don't fully understand where this vulnerability kicks in (other than <! ENTITY> which
I don't think I've ever needed to consume) but any change in default behaviour needs to
account for real-life usage, or it will simply become standard practice to switch it back to
"insecure" mode.
Regards,
--
Rowan Collins
[IMSoP]