Sitelet https://github.com/testable-eu/sast-testability-patterns/tree/master/PHP/30_anonymous_classes
Skip to content

Latest commit

 

History

History

Folders and files

README.md

Anonymous Classes

Tags: sast, php, php_v7.4.9

Version: v1.0

Description

Anonymous classes are classes without a specific name. They can be useful for one-off objects.

Overview

Instances has discovery rule discovery method rule successfull
1 Instance yes joern yes

1 Instance

This instance demonstrates the use of anonymous classes.

Code

<?php
$b = $_GET["p1"]; // source
$util = (new class {
    public function log($msg) {
        return $msg;
    }
});
// will print the input $b, XSS vulnerability
$a = $util->log($b);
echo $a; // sink

Instance Properties

category feature_vs_internal_api input_sanitizer negative_test_case source_and_sink
S0 FEATURE no no no
More

Compile

$_main:
     ; (lines=13, args=0, vars=3, tmps=9)
     ; (before optimizer)
     ; /.../PHP/30_anonymous_classes/1_instance_30_anonymous_classes/1_instance_30_anonymous_classes.php:1-10
     ; return  [] RANGE[0..0]
0000 T3 = FETCH_R (global) string("_GET")
0001 T4 = FETCH_DIM_R T3 string("p1")
0002 ASSIGN CV0($b) T4
0003 V6 = DECLARE_ANON_CLASS string("class@anonymous")
0004 V7 = NEW 0 V6
0005 DO_FCALL
0006 ASSIGN CV1($util) V7
0007 INIT_METHOD_CALL 1 CV1($util) string("log")
0008 SEND_VAR_EX CV0($b) 1
0009 V10 = DO_FCALL
0010 ASSIGN CV2($a) V10
0011 ECHO CV2($a)
0012 RETURN int(1)
LIVE RANGES:
     7: 0005 - 0006 (new)

class@anonymous::log:
     ; (lines=3, args=1, vars=1, tmps=0)
     ; (before optimizer)
     ; /.../PHP/30_anonymous_classes/1_instance_30_anonymous_classes/1_instance_30_anonymous_classes.php:4-6
     ; return  [] RANGE[0..0]
0000 CV0($msg) = RECV 1
0001 RETURN CV0($msg)
0002 RETURN null

Discovery

The opecode searches for DECLARE_ANON_CLASS in the opcode.

val x30 = (name, "30_anonymous_classes_iall", cpg.call(".*DECLARE_ANON_CLASS.*").location.toJson);
discovery method expected accuracy
joern Perfect

Measurement

Tool Comm_1 Comm_2 phpSAFE Progpilot RIPS WAP Ground Truth
08 Jun 2021 yes yes no no no no yes
17 May 2023 yes yes yes

Remediation

If named classes are easier for SAST tools, it should be possible to transform an anonymous class into a named class.