Bug #71559 [Asn]: Built-in HTTP server, we can downlaod file in web by bug

From: Date: Wed, 10 Feb 2016 22:21:52 +0000
Subject: Bug #71559 [Asn]: Built-in HTTP server, we can downlaod file in web by bug
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-199156@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71559&edit=1

 ID:                 71559
 Updated by:         ab@php.net
 Reported by:        setbanned at gmail dot com
 Summary:            Built-in HTTP server, we can downlaod file in web by
                     bug
 Status:             Assigned
 Type:               Bug
 Package:            Built-in web server
 Operating System:   Windows only
 PHP Version:        7.0.3
 Assigned To:        ab
 Block user comment: N
 Private report:     N

 New Comment:

Johannes, oh yeah, you've spotted it very well. The win32 namespace will cut off the trailing
dots and spaces. I'll prepare a patch for next RCs.

Thanks.


Previous Comments:
------------------------------------------------------------------------
[2016-02-10 17:01:19] johannes@php.net

Anatol, you have an idea? - This seems to be Windows-specific. 

In php_cli_server_dispatch() we see that the extension is not "php" (which is correct, as
the file extension is empty) so it dispatches a static file.  In php_cli_server_begin_send_static()
we do

1953    if (client->request.path_translated && strlen(client->request.path_translated)
!= client->request.path_translated_len) {
1954        /* can't handle paths that contain nul bytes */
1955        return php_cli_server_send_error_page(server, client, 400);
1956    }
1957
1958    fd = client->request.path_translated ? open(client->request.path_translated,
O_RDONLY): -1;

Which succeeds and opens "foo.php" when "foo.php." is requested.

------------------------------------------------------------------------
[2016-02-09 20:05:15] stas@php.net

Not a security issue since built-in server should not be used in production, but somebody may want
to look at it and fix it still.

------------------------------------------------------------------------
[2016-02-09 12:49:40] setbanned at gmail dot com

Description:
------------
Built-pool HTTP Downlaod Exploit.
Exploit By : TaWaN (2600 Thailand , KissShot - Studio , Tawan Naultang , Phitchayaphong Tantikul)

Software : PHP Built-in HTTP server
Version : 5.4.x , 5.6.x , 7.0.x
Os : Windows only

How to Exploit 

put . (dot) attach type in url

example : http://locahost:8000/index.php.

we can download file in Web and look code in file.

Test script:
---------------
image1 : http://www.mx7.com/i/680/lsaMUF.png
image2 : http://www.mx7.com/i/a49/RzFIyT.png
image3 : http://www.mx7.com/i/54b/2BjHvz.png
image4 : http://www.mx7.com/i/ee5/O2YHsc.png


Actual result:
--------------
we can downlaod file of the web.


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=71559&edit=1


Thread (1 message)

  • ab@php.net
  • Unknown Message
    • ab@php.net
« previous php.bugs (#199156) next »