News Feed
Sections




News Archive
Looking for more information on how to do PHP the right way? Check out PHP: The Right Way

Ilia Alshanetsky's Blog:
Another unserialize() abuse
March 23, 2006 @ 06:59:23

With yet another reason not to trust the users of your application (mainly the data they send you), Ilia Alshanetsky has details on an issue that could be caused by the unserialize() function in PHP.

While talking with PHP developers this morning I thought of another way unverified serialized strings could be abused. This exploit can only affect PHP 5 installs though, but given the growing market share of PHP 5 it is certainly something worth noting.

As you may know classes in PHP are allowed to implement a magic method called __wakeup() that contains operation that are to be performed when a class is deserialized. Some native classes like PDO implement this function with a goal of preventing database serialization and throw an error when it is used.

He uses an example with PDO and a string of a serialized "supposed PDO object" to illustrate how, without the proper handling, it could lead to a fatal error in the script. The end result of the fatal error, if displaying errors is still on, could be that somewhat sensitive information could be displayed to the viewer.

0 comments voice your opinion now!
unserialize abuse __wakeup fatal error display unserialize abuse __wakeup fatal error display


blog comments powered by Disqus

Similar Posts

Jamie Wong's Blog: Effective bugfixing techniques for PHP

International PHP Magazine: Poll Question: Features a PHP Editor Should Possess

Johannes Schluter's Blog: I have nothing to say - but maybe PHP...

Paul Reinheimer's Blog: Memcached Constants - Lame Code

Christopher Kunz's Blog: Warning about the article "SQL Injection" in current "PHP Magazin"


Community Events





Don't see your event here?
Let us know!


symfony2 release unittest refactor framework introduction install testing api community threedevsandamaybe developer laravel series opinion code interview podcast list language

All content copyright, 2014 PHPDeveloper.org :: info@phpdeveloper.org - Powered by the Solar PHP Framework