note 88627 added to function.eval

From: Date: Sun, 01 Feb 2009 17:04:24 +0000
Subject: note 88627 added to function.eval
Groups: php.notes 
Request: Send a blank email to php-notes+get-150067@lists.php.net to get a copy of this message
In response to some of the examples below: NEVER, EVER pass untrusted user input to eval(). You WILL get it wrong, and the result will be a gaping security hole. For instance, the "safe_eval" posted below by "maurice at chandoo dot de" will allow any function call with a space between the function name and the parentheses. <?php safe_eval("evil_func ();") ?> "SaferScript" by "udo dot schroeter at gmail dot com" is a bit more clever, using PHP's own tokenizer to catch obvious "hacks", such as: <?php evil_func (); evil_func (); evil_func/* ... */(); ?> It even prevent some dynamic function calls: <?php $func = "evil_func"; $func(); ?> But it's not clever enough to catch this: <?php $func = array("evil_func"); $func[0](); ?> Due to the complexity of the PHP language, there is bound to be other problems. The lesson is simple: eval() is for evaluating code written by yourself or a trusted user, e.g. pulled from a database or template file. Do not eval() user input! (See also this classic example of insufficient user input filtering: http://namb.la/popular/tech.html) ---- Server IP: 87.54.44.10 Probable Submitter: 82.211.214.44 ---- Manual Page -- http://www.php.net/manual/en/function.eval.php Edit -- https://master.php.net/note/edit/88627 Del: integrated -- https://master.php.net/note/delete/88627/integrated Del: useless -- https://master.php.net/note/delete/88627/useless Del: bad code -- https://master.php.net/note/delete/88627/bad+code Del: spam -- https://master.php.net/note/delete/88627/spam Del: non-english -- https://master.php.net/note/delete/88627/non-english Del: in docs -- https://master.php.net/note/delete/88627/in+docs Del: other reasons-- https://master.php.net/note/delete/88627 Reject -- https://master.php.net/note/reject/88627 Search -- https://master.php.net/manage/user-notes.php

« previous php.notes (#150067) next »