Bug #76519 [Nab]: include function access file written after question mark (?)

From: Date: Fri, 22 Jun 2018 10:28:54 +0000
Subject: Bug #76519 [Nab]: include function access file written after question mark (?)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-215852@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76519&edit=1 ID: 76519 Updated by: requinix@php.net Reported by: ziyahan at netsparker dot com Summary: include function access file written after question mark (?) Status: Not a bug Type: Bug Package: Filesystem function related Operating System: Ubuntu PHP Version: 7.0.30 -Assigned To: cmb +Assigned To: Block user comment: N Private report: N New Comment: That is a simple path traversal attack. https://www.google.com/search?q=path+traversal+attack The %3f and %253f is used to trick phpMyAdmin's checkPageValidity() into allowing the path. Why it even allows for anything other than a strict whitelist, let alone for question marks in the *filename*, I don't know... The question mark is not required for your proof of concept. ?target=ziyahan.txt/../../../../../../../../etc/passwd Previous Comments: ------------------------------------------------------------------------ [2018-06-22 10:27:29] cmb@php.net This does not look like a bug at all. You are checking if $page *starts* with "ziyahan.txt", and it does. This is certainly insufficient to validate a user supplied filename which you intend to pass to include. A properly configured open_basedir setting should prevent the inclusion of etc/passwd, though. ------------------------------------------------------------------------ [2018-06-22 10:06:32] ziyahan at netsparker dot com Description: ------------ a few days ago, a bug disclosure has been published: https://mp.weixin.qq.com/s?__biz=MzIzMTc1MjExOQ==&mid=2247485036&idx=1&sn=8e9647906c5d94f72564dec5bc51a2ab&chksm=e89e2eb4dfe9a7a28bff2efebb5b2723782dab660acff074c3f18c9e7dca924abdf3da618fb4&mpshare=1&scene=1&srcid=0621gAv1FMtrgoahD01psMZr&pass_ticket=LqhRfckPxAVG2dF%2FjxV%2F9%2FcEb5pShRgewJe%2FttJn2gIlIyGF%2FbsgGmzcbsV%2BLmMK#rd In disclosure, researcher use question mark (?) to bypass validity mechanism of phpmyadmin, however this trick can be used also in pure PHP script. I really don't understand how php interpreter evaluates question mark that given as param to include function. I have a code like below: <?php $page = $_REQUEST["target"]; if(strpos($page,"ziyahan.txt")===0) { include $page; } ?> It does not seem bypassable first, however I realize that a weird payload can bypass this ?target=ziyahan.txt%3f/../../../../../../../../etc/passwd I cannot understand how the payload has an affect there? It seems a bug. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=76519&edit=1

« previous php.bugs (#215852) next »