SAFECRAZE Telegram 33
assert()不再支持执行代码,少了一个执行任意代码的函数,这个影响还是挺大的。
create_function()函数被彻底移除了,我们又少了一个可以执行任意代码的函数。
libxml依赖最低2.9.0起,也就是说,XXE漏洞彻底消失在PHP里了。
继preg_replace()中的e模式被移除后,mb_ereg_replace()中的e模式也被彻底移除,再次少了一个执行任意代码的函数。
Phar中的元信息不再自动进行反序列化了,phar://触发反序列化的姿势也告别了。
parse_str()必须传入第二个参数了,少了一种全局变量覆盖的方法。
strpos()等函数中的参数必须要传入字符串了,以前通过传入数组进行弱类型利用的方法也失效了。
原文:
https://mp.weixin.qq.com/s?__biz=MzA4MDU0NzY4Ng==&mid=2459419731&idx=1&sn=e9fce415f04f41c748e63e148eb21295&chksm=88c1fe5abfb6774c57f1f0b5eb86ce36c7271d92d30285a6f16c2dfbdc53e319df692a61db53&mpshare=1&scene=23&srcid=1127g5eVPsYt4F1zjBX3gvSL&sharer_sharetime=1606447067642&sharer_shareid=7d5524e08e4120807f27747eea12baf7#rd 有安全研究者混入了PHP 8.0开发组!



tgoop.com/Safecraze/33
Create:
Last Update:

assert()不再支持执行代码,少了一个执行任意代码的函数,这个影响还是挺大的。
create_function()函数被彻底移除了,我们又少了一个可以执行任意代码的函数。
libxml依赖最低2.9.0起,也就是说,XXE漏洞彻底消失在PHP里了。
继preg_replace()中的e模式被移除后,mb_ereg_replace()中的e模式也被彻底移除,再次少了一个执行任意代码的函数。
Phar中的元信息不再自动进行反序列化了,phar://触发反序列化的姿势也告别了。
parse_str()必须传入第二个参数了,少了一种全局变量覆盖的方法。
strpos()等函数中的参数必须要传入字符串了,以前通过传入数组进行弱类型利用的方法也失效了。
原文:
https://mp.weixin.qq.com/s?__biz=MzA4MDU0NzY4Ng==&mid=2459419731&idx=1&sn=e9fce415f04f41c748e63e148eb21295&chksm=88c1fe5abfb6774c57f1f0b5eb86ce36c7271d92d30285a6f16c2dfbdc53e319df692a61db53&mpshare=1&scene=23&srcid=1127g5eVPsYt4F1zjBX3gvSL&sharer_sharetime=1606447067642&sharer_shareid=7d5524e08e4120807f27747eea12baf7#rd 有安全研究者混入了PHP 8.0开发组!

BY 信息安全狂热者




Share with your friend now:
tgoop.com/Safecraze/33

View MORE
Open in Telegram


Telegram News

Date: |

Add the logo from your device. Adjust the visible area of your image. Congratulations! Now your Telegram channel has a face Click “Save”.! There have been several contributions to the group with members posting voice notes of screaming, yelling, groaning, and wailing in different rhythms and pitches. Calling out the “degenerate” community or the crypto obsessives that engage in high-risk trading, Co-founder of NFT renting protocol Rentable World emiliano.eth shared this group on his Twitter. He wrote: “hey degen, are you stressed? Just let it out all out. Voice only tg channel for screaming”. Members can post their voice notes of themselves screaming. Interestingly, the group doesn’t allow to post anything else which might lead to an instant ban. As of now, there are more than 330 members in the group. Matt Hussey, editorial director of NEAR Protocol (and former editor-in-chief of Decrypt) responded to the news of the Telegram group with “#meIRL.” Although some crypto traders have moved toward screaming as a coping mechanism, several mental health experts call this therapy a pseudoscience. The crypto community finds its way to engage in one or the other way and share its feelings with other fellow members.
from us


Telegram 信息安全狂热者
FROM American