note 88627 added to function.eval
| From: | SrenLvborg at osu1 dot php dot net | Date: | Sun, 01 Feb 2009 17:04:24 +0000 |
| Subject: | note 88627 added to function.eval | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-150067@lists.php.net to get a copy of this message | ||
In response to some of the examples below: NEVER, EVER pass untrusted user input to eval(). You WILL
get it wrong, and the result will be a gaping security hole.
For instance, the "safe_eval" posted below by "maurice at chandoo dot de" will
allow any function call with a space between the function name and the parentheses.
<?php
safe_eval("evil_func ();")
?>
"SaferScript" by "udo dot schroeter at gmail dot com" is a bit more clever,
using PHP's own tokenizer to catch obvious "hacks", such as:
<?php
evil_func ();
evil_func
();
evil_func/* ... */();
?>
It even prevent some dynamic function calls:
<?php
$func = "evil_func";
$func();
?>
But it's not clever enough to catch this:
<?php
$func = array("evil_func");
$func[0]();
?>
Due to the complexity of the PHP language, there is bound to be other problems. The lesson is
simple: eval() is for evaluating code written by yourself or a trusted user, e.g. pulled from a
database or template file. Do not eval() user input! (See also this classic example of insufficient
user input filtering: http://namb.la/popular/tech.html)
----
Server IP: 87.54.44.10
Probable Submitter: 82.211.214.44
----
Manual Page -- http://www.php.net/manual/en/function.eval.php
Edit -- https://master.php.net/note/edit/88627
Del: integrated -- https://master.php.net/note/delete/88627/integrated
Del: useless -- https://master.php.net/note/delete/88627/useless
Del: bad code -- https://master.php.net/note/delete/88627/bad+code
Del: spam -- https://master.php.net/note/delete/88627/spam
Del: non-english -- https://master.php.net/note/delete/88627/non-english
Del: in docs -- https://master.php.net/note/delete/88627/in+docs
Del: other reasons-- https://master.php.net/note/delete/88627
Reject -- https://master.php.net/note/reject/88627
Search -- https://master.php.net/manage/user-notes.php