note 88627 deleted from function.eval by danbrown

From: Date: Sun, 01 Feb 2009 20:10:56 +0000
Subject: note 88627 deleted from function.eval by danbrown
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-150076@lists.php.net to get a copy of this message
Note Submitter: Sren Lvborg ---- In response to some of the examples below: NEVER, EVER pass untrusted user input to eval(). You WILL get it wrong, and the result will be a gaping security hole. For instance, the "safe_eval" posted below by "maurice at chandoo dot de" will allow any function call with a space between the function name and the parentheses. <?php safe_eval("evil_func ();") ?> "SaferScript" by "udo dot schroeter at gmail dot com" is a bit more clever, using PHP's own tokenizer to catch obvious "hacks", such as: <?php evil_func (); evil_func (); evil_func/* ... */(); ?> It even prevent some dynamic function calls: <?php $func = "evil_func"; $func(); ?> But it's not clever enough to catch this: <?php $func = array("evil_func"); $func[0](); ?> Due to the complexity of the PHP language, there is bound to be other problems. The lesson is simple: eval() is for evaluating code written by yourself or a trusted user, e.g. pulled from a database or template file. Do not eval() user input! (See also this classic example of insufficient user input filtering: http://namb.la/popular/tech.html)

« previous php.notes (#150076) next »