Bug #76519 [NEW]: include function access file written after question mark (?)
| From: | ziyahan at netsparker dot com | Date: | Fri, 22 Jun 2018 10:06:35 +0000 |
| Subject: | Bug #76519 [NEW]: include function access file written after question mark (?) | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-215850@lists.php.net to get a copy of this message | ||
From: ziyahan at netsparker dot com
Operating system: Ubuntu
PHP version: 7.0.30
Package: Filesystem function related
Bug Type: Bug
Bug description:include function access file written after question mark (?)
Description:
------------
a few days ago, a bug disclosure has been published:
https://mp.weixin.qq.com/s?__biz=MzIzMTc1MjExOQ==&mid=2247485036&idx=1&sn=8e9647906c5d94f72564dec5bc51a2ab&chksm=e89e2eb4dfe9a7a28bff2efebb5b2723782dab660acff074c3f18c9e7dca924abdf3da618fb4&mpshare=1&scene=1&srcid=0621gAv1FMtrgoahD01psMZr&pass_ticket=LqhRfckPxAVG2dF%2FjxV%2F9%2FcEb5pShRgewJe%2FttJn2gIlIyGF%2FbsgGmzcbsV%2BLmMK#rd
In disclosure, researcher use question mark (?) to bypass validity
mechanism of phpmyadmin, however this trick can be used also in pure PHP
script.
I really don't understand how php interpreter evaluates question mark
that given as param to include function.
I have a code like below:
<?php
$page = $_REQUEST["target"];
if(strpos($page,"ziyahan.txt")===0) {
include $page;
}
?>
It does not seem bypassable first, however I realize that a weird
payload can bypass this
?target=ziyahan.txt%3f/../../../../../../../../etc/passwd
I cannot understand how the payload has an affect there?
It seems a bug.
--
Edit bug report at https://bugs.php.net/bug.php?id=76519&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=76519&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=76519&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=76519&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=76519&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=76519&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=76519&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=76519&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=76519&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=76519&r=support
Expected behavior: https://bugs.php.net/fix.php?id=76519&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=76519&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=76519&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=76519&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=76519&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=76519&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=76519&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=76519&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=76519&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=76519&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=76519&r=mysqlcfg