From 3741554097cc73f03a9a6a4fa4d65dc01c120bd8 Mon Sep 17 00:00:00 2001 From: Ben Fuhrmannek Date: Fri, 6 Feb 2015 22:38:35 +0100 Subject: tests for eval white/blacklist + include white/blacklist --- tests/executor/eval_blacklist.phpt | 18 +++++++++++++++++ tests/executor/eval_blacklist_printf.phpt | 16 +++++++++++++++ .../eval_blacklist_printf_function_exists.phpt | 23 ++++++++++++++++++++++ tests/executor/eval_whitelist_absmax.phpt | 16 +++++++++++++++ tests/executor/eval_whitelist_call_user_func.phpt | 15 ++++++++++++++ tests/executor/function_whiletist_absmax.phpt | 15 -------------- tests/executor/function_whitelist_absmax.phpt | 15 ++++++++++++++ 7 files changed, 103 insertions(+), 15 deletions(-) create mode 100644 tests/executor/eval_blacklist.phpt create mode 100644 tests/executor/eval_blacklist_printf.phpt create mode 100644 tests/executor/eval_blacklist_printf_function_exists.phpt create mode 100644 tests/executor/eval_whitelist_absmax.phpt create mode 100644 tests/executor/eval_whitelist_call_user_func.phpt delete mode 100644 tests/executor/function_whiletist_absmax.phpt create mode 100644 tests/executor/function_whitelist_absmax.phpt (limited to 'tests/executor') diff --git a/tests/executor/eval_blacklist.phpt b/tests/executor/eval_blacklist.phpt new file mode 100644 index 0000000..586bebc --- /dev/null +++ b/tests/executor/eval_blacklist.phpt @@ -0,0 +1,18 @@ +--TEST-- +Testing: suhosin.executor.eval.blacklist=max +--SKIPIF-- + +--INI-- +suhosin.log.sapi=64 +suhosin.executor.disable_eval=0 +suhosin.executor.eval.blacklist=max +--FILE-- + +--EXPECTF-- +ALERT - function within eval blacklist called: max() (attacker 'REMOTE_ADDR not set', file '%s', line 4) + +Warning: max() has been disabled for security reasons in %s : eval()'d code on line 2 diff --git a/tests/executor/eval_blacklist_printf.phpt b/tests/executor/eval_blacklist_printf.phpt new file mode 100644 index 0000000..596036e --- /dev/null +++ b/tests/executor/eval_blacklist_printf.phpt @@ -0,0 +1,16 @@ +--TEST-- +Testing: suhosin.executor.eval.blacklist=printf via call_user_func +--SKIPIF-- + +--INI-- +suhosin.log.sapi=64 +suhosin.executor.disable_eval=0 +suhosin.executor.eval.blacklist=printf +--FILE-- + +--EXPECTF-- +ALERT - function within eval blacklist called: printf() (attacker 'REMOTE_ADDR not set', file '%s : eval()'d code', line 1) + +Warning: printf() has been disabled for security reasons in %s : eval()'d code on line 1 diff --git a/tests/executor/eval_blacklist_printf_function_exists.phpt b/tests/executor/eval_blacklist_printf_function_exists.phpt new file mode 100644 index 0000000..d9b842c --- /dev/null +++ b/tests/executor/eval_blacklist_printf_function_exists.phpt @@ -0,0 +1,23 @@ +--TEST-- +Testing: suhosin.executor.eval.blacklist=printf with function_exists() +--SKIPIF-- + +--INI-- +suhosin.log.sapi=64 +suhosin.executor.disable_eval=0 +suhosin.executor.eval.blacklist=printf,max +--FILE-- + +--EXPECTF-- +bool(true) +bool(false) +bool(true) +bool(false) +bool(true) + diff --git a/tests/executor/eval_whitelist_absmax.phpt b/tests/executor/eval_whitelist_absmax.phpt new file mode 100644 index 0000000..fff7345 --- /dev/null +++ b/tests/executor/eval_whitelist_absmax.phpt @@ -0,0 +1,16 @@ +--TEST-- +Testing: suhosin.executor.eval.whitelist=abs,max +--SKIPIF-- + +--INI-- +suhosin.log.sapi=64 +suhosin.executor.disable_eval=0 +suhosin.executor.eval.whitelist=abs,max +--FILE-- + +--EXPECTF-- + diff --git a/tests/executor/eval_whitelist_call_user_func.phpt b/tests/executor/eval_whitelist_call_user_func.phpt new file mode 100644 index 0000000..6f09b50 --- /dev/null +++ b/tests/executor/eval_whitelist_call_user_func.phpt @@ -0,0 +1,15 @@ +--TEST-- +Testing: suhosin.executor.eval.whitelist=printf via call_user_func +--SKIPIF-- + +--INI-- +suhosin.log.sapi=64 +suhosin.executor.eval.whitelist=call_user_func +--FILE-- + +--EXPECTF-- +ALERT - function outside of eval whitelist called: printf() (attacker 'REMOTE_ADDR not set', file '%s : eval()'d code', line 1) + +Warning: printf() has been disabled for security reasons in %s : eval()'d code on line 1 diff --git a/tests/executor/function_whiletist_absmax.phpt b/tests/executor/function_whiletist_absmax.phpt deleted file mode 100644 index f240e69..0000000 --- a/tests/executor/function_whiletist_absmax.phpt +++ /dev/null @@ -1,15 +0,0 @@ ---TEST-- -Testing: suhosin.executor.func.whitelist=abs,max ---SKIPIF-- - ---INI-- -suhosin.log.sapi=64 -suhosin.executor.func.whitelist=abs,max ---FILE-- - ---EXPECTF-- - diff --git a/tests/executor/function_whitelist_absmax.phpt b/tests/executor/function_whitelist_absmax.phpt new file mode 100644 index 0000000..f240e69 --- /dev/null +++ b/tests/executor/function_whitelist_absmax.phpt @@ -0,0 +1,15 @@ +--TEST-- +Testing: suhosin.executor.func.whitelist=abs,max +--SKIPIF-- + +--INI-- +suhosin.log.sapi=64 +suhosin.executor.func.whitelist=abs,max +--FILE-- + +--EXPECTF-- + -- cgit v1.3