Bug #68535 [Nab]: Uploaded files are not deleted because of missing impersonation

From: Date: Wed, 03 Dec 2014 07:30:53 +0000
Subject: Bug #68535 [Nab]: Uploaded files are not deleted because of missing impersonation
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-188892@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68535&edit=1 ID: 68535 Updated by: ab@php.net Reported by: lf at evasys dot de Summary: Uploaded files are not deleted because of missing impersonation Status: Not a bug Type: Bug Package: IIS related Operating System: Windows Server 2012 PHP Version: 5.5.19 Block user comment: N Private report: N New Comment: Yes, for IIS it makes pretty much sense IMO. Previous Comments: ------------------------------------------------------------------------ [2014-12-02 21:44:58] lf at evasys dot de Did you set fastcgi.impersonate = 1? ------------------------------------------------------------------------ [2014-12-02 17:37:02] ab@php.net Thanks for so detailed explanation. I've tried to repro this different ways including yours but still couldn't. Regarding the impersonation, you can see from these lines that it works with PHP, shown are the relevant lines where you've the "access denied" result. 5:05:54.9676630 PM php-cgi.exe 75828 CreateFile C:\inetpub\temp\php\php3C2A.tmp SUCCESS Desired Access: Read Attributes, Delete, Disposition: Open, Options: Non-Directory File, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, Impersonating: IIS APPPOOL\DefaultAppPool, OpenResult: Opened 5:05:54.9677298 PM php-cgi.exe 75828 QueryAttributeTagFile C:\inetpub\temp\php\php3C2A.tmp SUCCESS Attributes: A, ReparseTag: 0x0 5:05:54.9677732 PM php-cgi.exe 75828 SetDispositionInformationFile C:\inetpub\temp\php\php3C2A.tmp SUCCESS Delete: True 5:05:54.9678180 PM php-cgi.exe 75828 CloseFile C:\inetpub\temp\php\php3C2A.tmp SUCCESS However not using the built-in account but the app pool identity. So at least this topic is closed, PHP impersonation works (would even wonder if it wouldnt - that's the same API everywhere). Regarding the configuration of the built-in accounts and groups regarding security - yeah, there are probably numerous approaches besides the baselines. For instance while investigating I've found this one http://serverfault.com/questions/282806/should-i-impersonate-php-via-fastcgi where people don't even bother fastcgi.impersonate . So due to the above one can say that you're reporting clearly a configuration issue, not a PHP one. Thanks. ------------------------------------------------------------------------ [2014-12-02 13:05:13] lf at evasys dot de I added a screenshot with some marks of my procmon log: https://www.dropbox.com/s/wh4u4d61rxxj4jf/procmon.png?dl=0 Please see the explaination of the log: Block 1: This is the file upload and the origination of the upload temp file. As you can see, every action is done with impersonation od IUSR. Block 2: This is where the PHP script that was targeted by the HTML form is loaded. Also done with impersonation. Block 3: This is the result of a test my script does: **NOTE: I removed my log functions from the script. // IUSR has "Modify" rights on this folder $sFolder = "IUSR/"; $sTestFile = $sFolder."test.txt"; // Create test file $hFile = fopen($sTestFile, "w+"); fwrite($hFile, "test"); fclose($hFile); // Check if test file was created file_exists($sTestFile); // Delete test file unlink($sTestFile); // Check if test file was deleted file_exists($sTestFile); Also every action done with impersonation. Block 4: The same test but in another folder where I set IIS_IUSRS with "Modify" rights: // IIS_IUSRS group has "Modify" rights on this folder $sFolder = "IIS_IUSRS/"; ...like above... This proves, that my script can normally not write with IIS_IUSRS credentials. Also every action done with impersonation. Block 5: The same test, but now in upload_tmp_dir: // IUSR has "Modify" rights on this folder $sFolder = ini_get('upload_tmp_dir') ? ini_get('upload_tmp_dir') : sys_get_temp_dir(); ...like above... This test proves, that my configuration is valid for the upload_tmp_dir. Also every action done with impersonation. Block 6: The request ended, the uploaded file was not touched. In this case PHP will delete the file. But the access is denied and you can see that the impersonation is missing! procmon can be downloaded here: http://technet.microsoft.com/en-us/sysinternals/bb896645.aspx I also proved the log from progmon as native PML (procmon file) and CSV here: https://www.dropbox.com/sh/eyrxqjqkyqncqdk/AADNOnnfDZeUbW1k950LxryVa?dl=0 ------------------------------------------------------------------------ [2014-12-02 09:12:59] ab@php.net How exactly do you see it's missing? Thanks. ------------------------------------------------------------------------ [2014-12-02 09:08:12] lf at evasys dot de Status ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=68535 -- Edit this bug report at https://bugs.php.net/bug.php?id=68535&edit=1

« previous php.bugs (#188892) next »