Sec Bug->Bug #71559 [Opn]: Built-in HTTP server, we can downlaod file in web by bug
| From: | stas@php.net | Date: | Tue, 09 Feb 2016 20:05:16 +0000 |
| Subject: | Sec Bug->Bug #71559 [Opn]: Built-in HTTP server, we can downlaod file in web by bug | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-199139@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=71559&edit=1
ID: 71559
Updated by: stas@php.net
Reported by: setbanned at gmail dot com
Summary: Built-in HTTP server, we can downlaod file in web by
bug
Status: Open
-Type: Security
+Type: Bug
-Package: PHP options/info functions
+Package: Built-in web server
Operating System: Windows only
PHP Version: 7.0.3
Block user comment: N
Private report: Y
New Comment:
Not a security issue since built-in server should not be used in production, but somebody may want
to look at it and fix it still.
Previous Comments:
------------------------------------------------------------------------
[2016-02-09 12:49:40] setbanned at gmail dot com
Description:
------------
Built-pool HTTP Downlaod Exploit.
Exploit By : TaWaN (2600 Thailand , KissShot - Studio , Tawan Naultang , Phitchayaphong Tantikul)
Software : PHP Built-in HTTP server
Version : 5.4.x , 5.6.x , 7.0.x
Os : Windows only
How to Exploit
put . (dot) attach type in url
example : http://locahost:8000/index.php.
we can download file in Web and look code in file.
Test script:
---------------
image1 : http://www.mx7.com/i/680/lsaMUF.png
image2 : http://www.mx7.com/i/a49/RzFIyT.png
image3 : http://www.mx7.com/i/54b/2BjHvz.png
image4 : http://www.mx7.com/i/ee5/O2YHsc.png
Actual result:
--------------
we can downlaod file of the web.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=71559&edit=1