From f15b5aa308a46d555ecc09c075db8728a0895c23 Mon Sep 17 00:00:00 2001 From: Ben Fuhrmannek Date: Fri, 4 Mar 2016 14:50:51 +0100 Subject: test cases for eval+func black/whitelist --- tests/executor/eval_blacklist_printf.phpt | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) create mode 100644 tests/executor/eval_blacklist_printf.phpt (limited to 'tests/executor/eval_blacklist_printf.phpt') diff --git a/tests/executor/eval_blacklist_printf.phpt b/tests/executor/eval_blacklist_printf.phpt new file mode 100644 index 0000000..b66d457 --- /dev/null +++ b/tests/executor/eval_blacklist_printf.phpt @@ -0,0 +1,16 @@ +--TEST-- +Testing: suhosin.executor.eval.blacklist=printf via call_user_func +--SKIPIF-- + +--INI-- +suhosin.log.sapi=64 +suhosin.executor.disable_eval=0 +suhosin.executor.eval.blacklist=printf +--FILE-- + +--EXPECTF-- +ALERT - eval'd function blacklisted: printf() (attacker 'REMOTE_ADDR not set', file '%s : eval()'d code', line 1) + +Warning: printf() has been disabled for security reasons in %s : eval()'d code on line 1 -- cgit v1.3