Bug #76519 [Nab]: include function access file written after question mark (?)

From: Date: Fri, 22 Jun 2018 14:10:35 +0000
Subject: Bug #76519 [Nab]: include function access file written after question mark (?)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-215862@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76519&edit=1 ID: 76519 Updated by: requinix@php.net Reported by: ziyahan at netsparker dot com Summary: include function access file written after question mark (?) Status: Not a bug Type: Bug Package: Filesystem function related Operating System: Ubuntu PHP Version: 7.0.30 Block user comment: N Private report: N New Comment: Google, ziyahan. https://www.google.com/search?q=path+traversal+attack PHP is not examining each part of the path. It shouldn't need to. /x/../foo should always end up at /foo because that's how paths work. realpath() is the way to examine each part. realpath(/file/../foo) will fail. And yes, Linux does not allow /file/../foo. But Windows does. Previous Comments: ------------------------------------------------------------------------ [2018-06-22 12:05:02] ziyahan at netsparker dot com Are you serious? Do I look a one discuss here LFI? I am only trying to understand how the scenario below is possible: <?php include("wrong.php../../../../../../../etc/passwd"); ?> How can it return /etc/passwd In bash, you can try this command ie, cat wrong.php../../../../../etc/passwd Another imporant thing is that, "require" function does not evaluate the same payload in a same way. Could you please investigate the issue instead of judging me. ------------------------------------------------------------------------ [2018-06-22 11:55:38] spam2 at rhsoft dot net please inform yourself about path traversal attacks it's in doubt the underlying operating system which you can blame but to be honest: if you accept ../../ without test realpath() at your own you have nobody to blame but yourself ------------------------------------------------------------------------ [2018-06-22 11:52:02] ziyahan at netsparker dot com BTW, I forgot to say. For the case below: http://VULNERABLE_HOST/test/file.php?target=file.txt../../../../../../../etc/passwd I can reach /etc/passwd either way, existence of file.txt does not matter! ------------------------------------------------------------------------ [2018-06-22 11:41:19] ziyahan at netsparker dot com Hi again, There is a wrong assumption here. If OS would be Windows, you're right, payload can be considered OK. It is because in Windows, you will be able to access test/../../../file.txt, even if the directory test does not exist However, the OS that I worked on is Ubuntu. Yes, question mark is not mandatory. http://VULNERABLE_HOST/test/lfi.php?target=wrong.php../../../../../../../etc/passwd However, the file, wrong.php, does not exist actually:) How can I access the file /etc/Password by using the payload above? It seems weird, a bug. IF you don't think so, please explain how it can be possible? ------------------------------------------------------------------------ [2018-06-22 10:28:51] requinix@php.net That is a simple path traversal attack. https://www.google.com/search?q=path+traversal+attack The %3f and %253f is used to trick phpMyAdmin's checkPageValidity() into allowing the path. Why it even allows for anything other than a strict whitelist, let alone for question marks in the *filename*, I don't know... The question mark is not required for your proof of concept. ?target=ziyahan.txt/../../../../../../../../etc/passwd ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=76519 -- Edit this bug report at https://bugs.php.net/bug.php?id=76519&edit=1

« previous php.bugs (#215862) next »