Iconv, set the charset to RCE: Exploiting the glibc to hack the PHP engine
ambionics.io
ambionics.io
`libiconv` is a standalone library designed to provide encoding conversion on systems where the standard C library does not include this functionality, or where additional or different conversions are needed.
Despite their API compatibility, the two implementations have different internal symbols to avoid conflicts, allowing both to coexist on the same system if necessary. The two are maintained by separate teams within the GNU project, with glibc's version being tailored specifically for integration with the GNU C Library and `libiconv` serving as a more portable solution for a variety of environments.
There really should be an option to just these stupid fopen wrappers. The entire feature is profoundly misguided, and not even that useful.
The post says "Big applications (such as Drupal or Magento) have been disabling the phar:// protocol", but I can't even figure out how to do that in a quick check, other than a configure option.
There are so many implementations of charset conversions (each programming language has one or many implementations) and so many document format that allow to trigger them. If I write an internal backoffice application I should be able to constrain that any use of an exotic charset is suspect and should be blocked.
Given it’s pretty trivial to implement what filter is doing in procedural code, it doesn’t seem like the syntax sugar is worth it.
Any idea of the motivation for supporting building conversion chains this way and why the complexity in the base langue was deemed worth it?