note 88627 deleted from function.eval by danbrown
| From: | danbrown@php.net | Date: | Sun, 01 Feb 2009 20:10:56 +0000 |
| Subject: | note 88627 deleted from function.eval by danbrown | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-150076@lists.php.net to get a copy of this message | ||
Note Submitter: Sren Lvborg
----
In response to some of the examples below: NEVER, EVER pass untrusted user input to eval(). You WILL
get it wrong, and the result will be a gaping security hole.
For instance, the "safe_eval" posted below by "maurice at chandoo dot de" will
allow any function call with a space between the function name and the parentheses.
<?php
safe_eval("evil_func ();")
?>
"SaferScript" by "udo dot schroeter at gmail dot com" is a bit more clever,
using PHP's own tokenizer to catch obvious "hacks", such as:
<?php
evil_func ();
evil_func
();
evil_func/* ... */();
?>
It even prevent some dynamic function calls:
<?php
$func = "evil_func";
$func();
?>
But it's not clever enough to catch this:
<?php
$func = array("evil_func");
$func[0]();
?>
Due to the complexity of the PHP language, there is bound to be other problems. The lesson is
simple: eval() is for evaluating code written by yourself or a trusted user, e.g. pulled from a
database or template file. Do not eval() user input! (See also this classic example of insufficient
user input filtering: http://namb.la/popular/tech.html)