note 110552 added to function.unserialize

From: Date: Tue, 06 Nov 2012 00:27:25 +0000
Subject: note 110552 added to function.unserialize
Groups: php.notes 
Request: Send a blank email to php-notes+get-191679@lists.php.net to get a copy of this message
DO NOT USER the safe_unserialize() function by dzb@php-seo.com below. This attempt to protect unserialize() against malicious user input is just completely broken. There are many different tricks allowing to modify a serialized string in a way that it will cleanly pass the preg_match() checks and still exploits the application. NEVER EVER UNSERIALIZE() USER INPUT. ---- Server IP: 87.106.1.137 Probable Submitter: 78.34.71.151 ---- Manual Page -- http://www.php.net/manual/en/function.unserialize.php Edit -- https://master.php.net/note/edit/110552 Del: integrated -- https://master.php.net/note/delete/110552/integrated Del: useless -- https://master.php.net/note/delete/110552/useless Del: bad code -- https://master.php.net/note/delete/110552/bad+code Del: spam -- https://master.php.net/note/delete/110552/spam Del: non-english -- https://master.php.net/note/delete/110552/non-english Del: in docs -- https://master.php.net/note/delete/110552/in+docs Del: other reasons-- https://master.php.net/note/delete/110552 Reject -- https://master.php.net/note/reject/110552 Search -- https://master.php.net/manage/user-notes.php

« previous php.notes (#191679) next »