Bug #76519 [Nab]: include function access file written after question mark (?)
| From: | requinix@php.net | Date: | Fri, 22 Jun 2018 14:10:35 +0000 |
| Subject: | Bug #76519 [Nab]: include function access file written after question mark (?) | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-215862@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=76519&edit=1
ID: 76519
Updated by: requinix@php.net
Reported by: ziyahan at netsparker dot com
Summary: include function access file written after question
mark (?)
Status: Not a bug
Type: Bug
Package: Filesystem function related
Operating System: Ubuntu
PHP Version: 7.0.30
Block user comment: N
Private report: N
New Comment:
Google, ziyahan. https://www.google.com/search?q=path+traversal+attack
PHP is not examining each part of the path. It shouldn't need to. /x/../foo should always end
up at /foo because that's how paths work.
realpath() is the way to examine each part. realpath(/file/../foo) will fail.
And yes, Linux does not allow /file/../foo. But Windows does.
Previous Comments:
------------------------------------------------------------------------
[2018-06-22 12:05:02] ziyahan at netsparker dot com
Are you serious?
Do I look a one discuss here LFI?
I am only trying to understand how the scenario below is possible:
<?php
include("wrong.php../../../../../../../etc/passwd");
?>
How can it return /etc/passwd
In bash, you can try this command ie, cat wrong.php../../../../../etc/passwd
Another imporant thing is that,
"require" function does not evaluate the same payload in a same way.
Could you please investigate the issue instead of judging me.
------------------------------------------------------------------------
[2018-06-22 11:55:38] spam2 at rhsoft dot net
please inform yourself about path traversal attacks
it's in doubt the underlying operating system which you can blame but to be honest: if you
accept ../../ without test realpath() at your own you have nobody to blame but yourself
------------------------------------------------------------------------
[2018-06-22 11:52:02] ziyahan at netsparker dot com
BTW, I forgot to say. For the case below:
http://VULNERABLE_HOST/test/file.php?target=file.txt../../../../../../../etc/passwd
I can reach /etc/passwd either way, existence of file.txt does not matter!
------------------------------------------------------------------------
[2018-06-22 11:41:19] ziyahan at netsparker dot com
Hi again,
There is a wrong assumption here.
If OS would be Windows, you're right, payload can be considered OK.
It is because in Windows, you will be able to access test/../../../file.txt, even if the directory
test does not exist
However, the OS that I worked on is Ubuntu.
Yes, question mark is not mandatory.
http://VULNERABLE_HOST/test/lfi.php?target=wrong.php../../../../../../../etc/passwd
However, the file, wrong.php, does not exist actually:)
How can I access the file /etc/Password by using the payload above?
It seems weird, a bug.
IF you don't think so, please explain how it can be possible?
------------------------------------------------------------------------
[2018-06-22 10:28:51] requinix@php.net
That is a simple path traversal attack. https://www.google.com/search?q=path+traversal+attack
The %3f and %253f is used to trick phpMyAdmin's checkPageValidity() into allowing the path. Why
it even allows for anything other than a strict whitelist, let alone for question marks in the
*filename*, I don't know...
The question mark is not required for your proof of concept.
?target=ziyahan.txt/../../../../../../../../etc/passwd
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=76519
--
Edit this bug report at https://bugs.php.net/bug.php?id=76519&edit=1