php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #67356 php loophole GBK
Submitted: 2014-05-29 03:33 UTC Modified: 2014-06-13 14:00 UTC
From: xiaobianmail at 126 dot com Assigned:
Status: Not a bug Package: *General Issues
PHP Version: 5.5.12 OS: linux
Private report: No CVE-ID: None
Welcome back! If you're the original bug submitter, here's where you can edit the bug or add additional notes.
If you forgot your password, you can retrieve your password here.
Password:
Status:
Package:
Bug Type:
Summary:
From: xiaobianmail at 126 dot com
New email:
PHP Version: OS:

 

 [2014-05-29 03:33 UTC] xiaobianmail at 126 dot com
Description:
------------
When the page encoding is gbk, this code will be fatal error.

>php -r 'var_dump("運");'

Parse error: syntax error, unexpected end of file, expecting variable (T_VARIABLE) or ${ (T_DOLLAR_OPEN_CURLY_BRACES) or {$ (T_CURLY_OPEN) in Command line code on line 1

Test script:
---------------
>php -r 'var_dump("運");'

Parse error: syntax error, unexpected end of file, expecting variable (T_VARIABLE) or ${ (T_DOLLAR_OPEN_CURLY_BRACES) or {$ (T_CURLY_OPEN) in Command line code on line 1

<?php
//126 GBK error 
$count = $count2 = 0;
for($h = hexdec("8100"); $h <= hexdec("fe00"); $h = $h + 256){
    $i=0;
    for($l=hexdec("0040");$l<=hexdec("00fe");$l++){
       $char16 = dechex($h+$l);
       if(substr($char16,2,2) == '5c'){
           echo pack("n*",$h+$l)."<br />";
           $count2++;
        }
        $i++;
        $count++;
    }
}
echo $count;
echo"<br />";
echo $count2;


Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2014-05-29 03:38 UTC] xiaobianmail at 126 dot com
php 5.3 5.4 5.5 ....ALL Version
linux windows
 [2014-05-29 04:51 UTC] stas@php.net
-Type: Security +Type: Bug
 [2014-05-29 05:44 UTC] xiaobianmail at 126 dot com
My solution :
1.str_replace("\\", " ", "XXXXXX");
2.mb_substr("XXXXXX", 0, 1, "gbk");
 [2014-05-29 08:05 UTC] requinix@php.net
-Status: Open +Status: Not a bug
 [2014-05-29 08:05 UTC] requinix@php.net
As you've seen, CP936 (which supports GBK) encodes 運 as ß\. This results in the characters
  var_dump("ß\") // 0xDF 0x5C
and the unterminated string is what PHP is complaining about.

Fun fact: that problem right there is why CP936 is one of the very few encodings that allows SQL injection via Unicode.

CP936 just isn't safe. Use a different encoding in your console or find another way to represent that character (and the others like it) in code.
 [2014-06-13 04:53 UTC] xiaobianmail at 126 dot com
5c problem(CP936、Shift_JIS、windows-31j、sjis、MS932、EUC_JP)
For PHP security, I can only use the mbstring.
 [2014-06-13 14:00 UTC] yohgaki@php.net
If you would like to use SJIS like encoding, you _must_ use zend.multibyte.
Please read the manual.
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Thu Oct 08 03:00:02 2026 UTC