frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: PHP 8 disable_functions bypass PoC

https://github.com/m0x41nos/TimeAfterFree
24•m0x41nos•2h ago

Comments

altairprime•1h ago
Tell us more about how you searched for and uncovered this? Do you normally use PHP? What disclosure process did you use?
calvinmorrison•1h ago
That's a nice find. People rely a little heavily on this, and it only says in the manual "This directive allows certain functions to be disabled." but its not a security sandbox.

I think PHP has in the past explicitly stated its not a security feature.

There have been a few issues over the years with this.

Anyway - good OS security is required anytime you run software!

heres one from 6 years ago https://bugs.php.net/bug.php?id=76047

kadoban•1h ago
> I think PHP has in the past explicitly stated its not a security feature.

I'm struggling to think what it's for then?

turbert•53m ago
likely intended more as a lint than a security feature, it's not unusual to want to exclude commonly misused features from your code and any libraries you use.

Knowing the mess that is the php standard library, I imagine many applications would want to just straight up ban the really bad parts.

calvinmorrison•50m ago
a lazy security feature that stops 90% of problems?
duskwuff•48m ago
> I'm struggling to think what it's for then?

Placating some users - mainly shared web hosting providers - who still think that disabling functions like system() and exec() is an effective security measure.

halb•1h ago
there was a php-only million-rows challenge that was posted here recently. This uaf offers the opportunity for the funniest solution.
turbert•59m ago
from a quick skim, it looks like the underlying bug is just not handling object resurrection[1] at all (FreeMe adds a reference to $array while its destructor is called).

I'm not really familiar with PHP but this seems like a surprising oversight for a popular language. Does PHP just not care about memory corruption? The fact that it is this easy is far more surprising than it being used to circumvent a questionable security feature.

[1] https://en.wikipedia.org/wiki/Object_resurrection

The workers behind Meta’s smart glasses can see everything

https://www.svd.se/a/K8nrV4/metas-ai-smart-glasses-and-data-privacy-concerns-workers-say-we-see-e...
667•sandbach•4h ago•375 comments

OpenClaw Exposure Watchboard

https://openclaw.allegro.earth/
27•fanweixiao•36m ago•12 comments

Show HN: I built a sub-500ms latency voice agent from scratch

https://www.ntik.me/posts/voice-agent
214•nicktikhonov•6h ago•62 comments

Closure of the Weatheradio Service in Canada

https://www.rac.ca/rac-responds-to-the-closure-of-the-weatherradio-service-in-canada/
87•da768•4h ago•39 comments

Seed of Might Color Correction Process (2023) [pdf]

https://andrewvanner.github.io/som/SoM_CC_Process_Day.pdf
74•haunter•4h ago•16 comments

What are your guilty displeasures?

https://www.hopefulmons.com/p/what-are-your-guilty-displeasures
28•aregue•1d ago•22 comments

How to Build Your Own Quantum Computer

https://physics.aps.org/articles/v19/24
40•tzury•4h ago•11 comments

British Columbia to end time changes, adopt year-round daylight time

https://www.cbc.ca/news/canada/british-columbia/b-c-adopting-year-round-daylight-time-9.7111657
487•ireflect•6h ago•264 comments

New iPad Air, powered by M4

https://www.apple.com/newsroom/2026/03/apple-introduces-the-new-ipad-air-powered-by-m4/
336•Garbage•13h ago•538 comments

First in-utero stem cell therapy for fetal spina bifida repair is safe: study

https://health.ucdavis.edu/news/headlines/first-ever-in-utero-stem-cell-therapy-for-fetal-spina-b...
256•gmays•12h ago•50 comments

RCade: Building a Community Arcade Cabinet

https://www.frankchiarulli.com/blog/building-the-rcade/
56•evakhoury•4d ago•8 comments

The 185-Microsecond Type Hint

https://blog.sturdystatistics.com/posts/type_hint/
47•kianN•5h ago•3 comments

Against Query Based Compilers

https://matklad.github.io/2026/02/25/against-query-based-compilers.html
30•surprisetalk•1d ago•10 comments

Show HN: Govbase – Follow a bill from source text to news bias to social posts

https://govbase.com
162•foxfoxx•10h ago•72 comments

The Cathode Ray Tube site

https://www.crtsite.com/didactic-crt.html
13•joebig•1d ago•0 comments

Motorola announces a partnership with GrapheneOS

https://motorolanews.com/motorola-three-new-b2b-solutions-at-mwc-2026/
2083•km•20h ago•743 comments

Programmable Cryptography

https://0xparc.org/writings/programmable-cryptography-1
50•fi-le•2d ago•26 comments

Welcome (back) to Macintosh

https://take.surf/2026/03/01/welcome-back-to-macintosh
267•Udo_Schmitz•6h ago•182 comments

Show HN: Giggles – A batteries-included React framework for TUIs

https://github.com/zion-off/giggles
4•ajz317•57m ago•4 comments

iPhone 17e

https://www.apple.com/newsroom/2026/03/apple-introduces-iphone-17e/
209•meetpateltech•13h ago•283 comments

Ask HN: Who is hiring? (March 2026)

176•whoishiring•11h ago•227 comments

Show HN: Visual Lambda Calculus – a thesis project (2008) revived for the web

https://github.com/bntre/visual-lambda
23•bntr•2d ago•4 comments

Inside the M4 Apple Neural Engine, Part 1: Reverse Engineering

https://maderix.substack.com/p/inside-the-m4-apple-neural-engine
279•zdw•1d ago•74 comments

Launch HN: OctaPulse (YC W26) – Robotics and computer vision for fish farming

67•rohxnsxngh•10h ago•30 comments

"That Shape Had None" – A Horror of Substrate Independence (Short Fiction)

https://starlightconvenience.net/#that-shape-had-none
83•casmalia•8h ago•15 comments

LFortran compiles fpm

https://lfortran.org/blog/2026/02/lfortran-compiles-fpm/
53•wtlin•3d ago•21 comments

Reflex (YC W23) Is Hiring Software Engineers – Python

https://www.ycombinator.com/companies/reflex/jobs
1•apetuskey•10h ago

Ask HN: Who wants to be hired? (March 2026)

77•whoishiring•11h ago•191 comments

Show HN: Pianoterm – Run shell commands from your Piano. A Linux CLI tool

https://github.com/vustagc/pianoterm
42•vustagc•6h ago•15 comments

Parallel coding agents with tmux and Markdown specs

https://schipper.ai/posts/parallel-coding-agents/
129•schipperai•13h ago•103 comments