note 45503 deleted from function.unserialize by aharvey

From: Date: Tue, 06 Nov 2012 01:19:04 +0000
Subject: note 45503 deleted from function.unserialize by aharvey
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-191691@lists.php.net to get a copy of this message
Note Submitter: hfuecks at phppatterns dot com ---- If you are accepting a serialized string from an untrusted source (e.g. generated in Javascript), you need to be careful to check that it doesn't result in "unexpected" objects being created when you unserialize it. The following function pulls out the class names of all objects in a _valid_ serialized string. It works by first removing an serialized string values (which might contain serialized object syntax) then pulling out the class names from the remaining string. The returned value is a unique list of class names which the serialized string contains. Note it assumes the serialized string is valid (that it will be accepted by unserialize()). There may be invalid serialized strings that could trick this function but these should fail when unserialized. <?php function getSerializedClassNames($string) { // Stip any string representations (which might contain object syntax) $string = preg_replace('/s:[0-9]+:".*"/Us','',$string); // Pull out the class named preg_match_all('/O:[0-9]+:"(.*)"/U', $string, $matches, PREG_PATTERN_ORDER); // Make sure names are unique (same object serialized twice) return array_unique($matches[1]); } ?> Unit tests for a version of this function can be found at: http://cvs.sourceforge.net/viewcvs.py/xmlrpccom /scriptserver/tests/php/classparser.test.php?view=auto See also the discussion here; http://marc.theaimsgroup.com/?t=109439858700006&r=1&w=2 http://marc.theaimsgroup.com/?l=php-dev&m=109444959007776&w=2

« previous php.notes (#191691) next »