Re: Possible Parse Bomb

From: Date: Sat, 09 Dec 2000 12:54:01 +0000
Subject: Re: Possible Parse Bomb
References: 1  Groups: php.qa 
Request: Send a blank email to php-qa+get-1776@lists.php.net to get a copy of this message
Sascha spoke: > > Thoughts, comments? > > I doubt this is a deterministic problem and that it can be > recreated by querying a web-server even a billion times. It > is impossible to prove a specific detect does not exist (in > any given implementation). What you can prove is that you > cannot create the necessary circumstances to show that the > problem exists. I agree that it is likely that this problem can not be recreated by brute force testing. However, if we can prove that it is highly unlikely that the parser will behave badly under normal conditions, then we can eliminate one class of worries. > What James might have observed is someone changing the > configuration file on our web-server and restarting it too > early or something like that. We can't protect people from the scenario that you present. However, we should be able to offer them the assurance that, under most conditions, PHP will not display unparsed code. (Also, the scenario that you present is quite plausable - if the sysadmin mungs a conf file, then it would be easy enough for raw code to be dumped straight to the browser.) --zak

« previous php.qa (#1776) next »