Bug #76519 [Com]: include function access file written after question mark (?)
| From: | ziyahan at netsparker dot com | Date: | Fri, 22 Jun 2018 11:41:20 +0000 |
| Subject: | Bug #76519 [Com]: include function access file written after question mark (?) | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-215853@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=76519&edit=1
ID: 76519
Comment by: ziyahan at netsparker dot com
Reported by: ziyahan at netsparker dot com
Summary: include function access file written after question
mark (?)
Status: Not a bug
Type: Bug
Package: Filesystem function related
Operating System: Ubuntu
PHP Version: 7.0.30
Block user comment: N
Private report: N
New Comment:
Hi again,
There is a wrong assumption here.
If OS would be Windows, you're right, payload can be considered OK.
It is because in Windows, you will be able to access test/../../../file.txt, even if the directory
test does not exist
However, the OS that I worked on is Ubuntu.
Yes, question mark is not mandatory.
http://VULNERABLE_HOST/test/lfi.php?target=wrong.php../../../../../../../etc/passwd
However, the file, wrong.php, does not exist actually:)
How can I access the file /etc/Password by using the payload above?
It seems weird, a bug.
IF you don't think so, please explain how it can be possible?
Previous Comments:
------------------------------------------------------------------------
[2018-06-22 10:28:51] requinix@php.net
That is a simple path traversal attack. https://www.google.com/search?q=path+traversal+attack
The %3f and %253f is used to trick phpMyAdmin's checkPageValidity() into allowing the path. Why
it even allows for anything other than a strict whitelist, let alone for question marks in the
*filename*, I don't know...
The question mark is not required for your proof of concept.
?target=ziyahan.txt/../../../../../../../../etc/passwd
------------------------------------------------------------------------
[2018-06-22 10:27:29] cmb@php.net
This does not look like a bug at all. You are checking if $page
*starts* with "ziyahan.txt", and it does. This is certainly
insufficient to validate a user supplied filename which you intend
to pass to include.
A properly configured open_basedir setting should prevent the
inclusion of etc/passwd, though.
------------------------------------------------------------------------
[2018-06-22 10:06:32] ziyahan at netsparker dot com
Description:
------------
a few days ago, a bug disclosure has been published:
https://mp.weixin.qq.com/s?__biz=MzIzMTc1MjExOQ==&mid=2247485036&idx=1&sn=8e9647906c5d94f72564dec5bc51a2ab&chksm=e89e2eb4dfe9a7a28bff2efebb5b2723782dab660acff074c3f18c9e7dca924abdf3da618fb4&mpshare=1&scene=1&srcid=0621gAv1FMtrgoahD01psMZr&pass_ticket=LqhRfckPxAVG2dF%2FjxV%2F9%2FcEb5pShRgewJe%2FttJn2gIlIyGF%2FbsgGmzcbsV%2BLmMK#rd
In disclosure, researcher use question mark (?) to bypass validity mechanism of phpmyadmin, however
this trick can be used also in pure PHP script.
I really don't understand how php interpreter evaluates question mark that given as param to
include function.
I have a code like below:
<?php
$page = $_REQUEST["target"];
if(strpos($page,"ziyahan.txt")===0) {
include $page;
}
?>
It does not seem bypassable first, however I realize that a weird payload can bypass this
?target=ziyahan.txt%3f/../../../../../../../../etc/passwd
I cannot understand how the payload has an affect there?
It seems a bug.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=76519&edit=1