Sec Bug->Bug #75889 [Opn]: Overloading disk with temporary files
| From: | stas@php.net | Date: | Thu, 01 Feb 2018 07:41:26 +0000 |
| Subject: | Sec Bug->Bug #75889 [Opn]: Overloading disk with temporary files | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-213774@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75889&edit=1
ID: 75889
Updated by: stas@php.net
Reported by: c dot r dot l dot f at yandex dot ru
Summary: Overloading disk with temporary files
Status: Open
-Type: Security
+Type: Bug
Package: FPM related
Operating System: Linux
PHP Version: 7.1.13
Block user comment: N
Private report: Y
Previous Comments:
------------------------------------------------------------------------
[2018-02-01 02:21:53] c dot r dot l dot f at yandex dot ru
Yep, I just checked it, it's not reproducible when file_uploads = Off.
------------------------------------------------------------------------
[2018-02-01 02:13:29] stas@php.net
So do I understand correctly the problem does not exist when file uploads are disabled?
------------------------------------------------------------------------
[2018-02-01 02:06:42] c dot r dot l dot f at yandex dot ru
In default installations files uploads is always on, so any host that satisfies the dependencies
(PHP+NGINX) can be attacked.
Please look video PoC:
https://alt3r.eg0.ru/p0c5/12a636fcab5953233706dadacfff3ba8.avi
------------------------------------------------------------------------
[2018-02-01 01:36:58] stas@php.net
Isn't that always the case when uploads are allowed - you can upload files until out of disk
space, absent other limitations like quotas, etc.?
------------------------------------------------------------------------
[2018-02-01 01:01:32] c dot r dot l dot f at yandex dot ru
The problem is that PHP does not delete created temporary files (rfc1867) after connection is
closed.
In the provided scenario, NGINX closes the connection before PHP writes something in it. Judging by
the logs of strace, PHP gets SIGPIPE and for some reasons does not clear temporary files.
Thus, the attacker can upload temporary files while disk space is available. Only reboot or manual
deleting this files will help.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=75889
--
Edit this bug report at https://bugs.php.net/bug.php?id=75889&edit=1