eval(gzuncompress(base64_decode('eF...
Classic PHP injection hack. eval(gzuncompress(base64_decode('eF...
Classic PHP injection hack.Is it ever used by legitimate scripts?
I wish.
> Is it ever used by legitimate scripts?
There are edge cases, but I haven't found a need for it in almost a decade of coding. I really wish there was an option to disable it while compiling the PHP binary or using php.ini ...
Keep in mind, removing eval wouldn't have stopped this hack. It would have simply made it more obvious, since they wouldn't be able to encode/compress their injected code.
Anyways, disabling eval doesn't buy you much: If you really want to execute code, write it to a file and then require that file. You can plug that one by making all directories you can load code from unwriteable, but then I could just go and call create_user_func() which is eval in disguise.
Eval is used by most attackers to avoid detection. A one liner add to the end of a legitimate random php file along with extra padding to push it off the screen will make most users to miss it.
Creating directories and files not only requires appropriate permissions but is also more susceptible to be noticed by a user browsing through them.
http://stackoverflow.com/questions/1865020/php-how-to-disabl...
That could happen in any language / framework / situation. It's rogue code that got trusted.
[1] http://php.net/manual/en/ini.core.php#ini.disable-functions
Edit: Also, as noted below, this wouldn't prevent this or many other similar hacks as you need write access to the PHP script to put the eval in in the first place, so you could just write other code in there directly (and pull in extra scripts to execute by writing to disk etc. if necessary). Eval is typically dangerous, in its own right, when it is used by the legitimate developer who then allows unchecked code to be passed to it.
Just remove anything you use. I use cURL, so I took it out.
Only internal functions can be disabled using this directive.
It is possible to generate something like a list of all available internal functions, eval is missing here:
$arr = get_defined_functions();
var_dump($arr['internal']);
The Suhosin extension will let you block eval, if it is available:http://www.hardened-php.net/suhosin/configuration.html#suhos...