note 110552 added to function.unserialize
| From: | Anonymous | Date: | Tue, 06 Nov 2012 00:27:25 +0000 |
| Subject: | note 110552 added to function.unserialize | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-191679@lists.php.net to get a copy of this message | ||
DO NOT USER the safe_unserialize() function by dzb@php-seo.com below.
This attempt to protect unserialize() against malicious user input is just completely broken. There
are many different tricks allowing to modify a serialized string in a way that it will cleanly pass
the preg_match() checks and still exploits the application.
NEVER EVER UNSERIALIZE() USER INPUT.
----
Server IP: 87.106.1.137
Probable Submitter: 78.34.71.151
----
Manual Page -- http://www.php.net/manual/en/function.unserialize.php
Edit -- https://master.php.net/note/edit/110552
Del: integrated -- https://master.php.net/note/delete/110552/integrated
Del: useless -- https://master.php.net/note/delete/110552/useless
Del: bad code -- https://master.php.net/note/delete/110552/bad+code
Del: spam -- https://master.php.net/note/delete/110552/spam
Del: non-english -- https://master.php.net/note/delete/110552/non-english
Del: in docs -- https://master.php.net/note/delete/110552/in+docs
Del: other reasons-- https://master.php.net/note/delete/110552
Reject -- https://master.php.net/note/reject/110552
Search -- https://master.php.net/manage/user-notes.php