note 45503 added to function.unserialize

From: Date: Thu, 09 Sep 2004 11:14:01 +0000
Subject: note 45503 added to function.unserialize
Groups: php.notes 
Request: Send a blank email to php-notes+get-76312@lists.php.net to get a copy of this message
If you are accepting a serialized string from an untrusted source (e.g. generated in Javascript), you need to be careful to check that it doesn't result in "unexpected" objects being created when you unserialize it. The following function pulls out the class names of all objects in a _valid_ serialized string. It works by first removing an serialized string values (which might contain serialized object syntax) then pulling out the class names from the remaining string. The returned value is a unique list of class names which the serialized string contains. Note it assumes the serialized string is valid (that it will be accepted by unserialize()). There may be invalid serialized strings that could trick this function but these should fail when unserialized. <?php function getSerializedClassNames($string) { // Stip any string representations (which might contain object syntax) $string = preg_replace('/s:[0-9]+:".*"/Us','',$string); // Pull out the class named preg_match_all('/O:[0-9]+:"(.*)"/U', $string, $matches, PREG_PATTERN_ORDER); // Make sure names are unique (same object serialized twice) return array_unique($matches[1]); } ?> Unit tests for a version of this function can be found at: http://cvs.sourceforge.net/viewcvs.py/xmlrpccom /scriptserver/tests/php/classparser.test.php?view=auto See also the discussion here; http://marc.theaimsgroup.com/?t=109439858700006&r=1&w=2 http://marc.theaimsgroup.com/?l=php-dev&m=109444959007776&w=2 ---- Manual Page -- http://www.php.net/manual/en/function.unserialize.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+45503 Delete -- http://master.php.net/manage/user-notes.php?action=delete+45503&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+45503&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#76312) next »