Tags: sast, php, php_v7.4.9
Version: v1.0
Anonymous classes are classes without a specific name. They can be useful for one-off objects.
| Instances | has discovery rule | discovery method | rule successfull |
|---|---|---|---|
| 1 Instance | yes | joern | yes |
This instance demonstrates the use of anonymous classes.
<?php
$b = $_GET["p1"]; // source
$util = (new class {
public function log($msg) {
return $msg;
}
});
// will print the input $b, XSS vulnerability
$a = $util->log($b);
echo $a; // sink| category | feature_vs_internal_api | input_sanitizer | negative_test_case | source_and_sink |
|---|---|---|---|---|
| S0 | FEATURE | no | no | no |
More
$_main:
; (lines=13, args=0, vars=3, tmps=9)
; (before optimizer)
; /.../PHP/30_anonymous_classes/1_instance_30_anonymous_classes/1_instance_30_anonymous_classes.php:1-10
; return [] RANGE[0..0]
0000 T3 = FETCH_R (global) string("_GET")
0001 T4 = FETCH_DIM_R T3 string("p1")
0002 ASSIGN CV0($b) T4
0003 V6 = DECLARE_ANON_CLASS string("class@anonymous")
0004 V7 = NEW 0 V6
0005 DO_FCALL
0006 ASSIGN CV1($util) V7
0007 INIT_METHOD_CALL 1 CV1($util) string("log")
0008 SEND_VAR_EX CV0($b) 1
0009 V10 = DO_FCALL
0010 ASSIGN CV2($a) V10
0011 ECHO CV2($a)
0012 RETURN int(1)
LIVE RANGES:
7: 0005 - 0006 (new)
class@anonymous::log:
; (lines=3, args=1, vars=1, tmps=0)
; (before optimizer)
; /.../PHP/30_anonymous_classes/1_instance_30_anonymous_classes/1_instance_30_anonymous_classes.php:4-6
; return [] RANGE[0..0]
0000 CV0($msg) = RECV 1
0001 RETURN CV0($msg)
0002 RETURN nullThe opecode searches for DECLARE_ANON_CLASS in the opcode.
val x30 = (name, "30_anonymous_classes_iall", cpg.call(".*DECLARE_ANON_CLASS.*").location.toJson);| discovery method | expected accuracy |
|---|---|
| joern | Perfect |
| Tool | Comm_1 | Comm_2 | phpSAFE | Progpilot | RIPS | WAP | Ground Truth |
|---|---|---|---|---|---|---|---|
| 08 Jun 2021 | yes | yes | no | no | no | no | yes |
| 17 May 2023 | yes | yes | yes |