Bug #75840 [Opn]: when i load COM('WScript.shell') and call exec('cmd.exe /c whoami') to execute
| From: | ab@php.net | Date: | Sat, 07 Jul 2018 16:04:12 +0000 |
| Subject: | Bug #75840 [Opn]: when i load COM('WScript.shell') and call exec('cmd.exe /c whoami') to execute | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-216204@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75840&edit=1
ID: 75840
Updated by: ab@php.net
Reported by: zhang_xiaobao at venustech dot com dot cn
Summary: when i load COM('WScript.shell') and call
exec('cmd.exe /c whoami') to execute
Status: Open
Type: Bug
Package: COM related
Operating System: windows
PHP Version: 7.0.27
Block user comment: N
Private report: N
New Comment:
Any news on this?
Thanks.
Previous Comments:
------------------------------------------------------------------------
[2018-01-23 02:42:33] zhang_xiaobao at venustech dot com dot cn
Thank you for your suggestion,I'll retest this vulnerability later on your advice and send you
a document on the details of the vulnerability.
------------------------------------------------------------------------
[2018-01-22 11:57:16] ab@php.net
Thanks for sending the crash dump. Unfortunately i could only see a few stack frames, because the
libhttpd.dll is missing the debug symbols and they're not provided by XAMPP, too. Eg.
> libhttpd.dll!_ap_run_generate_log_id@12() + 7350 bytes Unknown No symbols loaded.
[Frames below may be incorrect and/or missing, no symbols loaded for libhttpd.dll] Annotated
Frame
libhttpd.dll!_ap_signal_parent@4() + 7799 bytes Unknown No symbols loaded.
libhttpd.dll!_ap_run_mpm@12() + 43 bytes Unknown No symbols loaded.
httpd.exe!OPENSSL_Applink() + 2950 bytes Unknown No symbols loaded.
Please also note, that the lack of debug symbols is a usual thing, if no official builds are used.
From the code flow, the command execution would normally block until the command has finished. Every
thread has it's own structures, that would be destroyed separately.
However one guess that i have is about OpenSSL. The report is about 7.0.27 which we officially link
with OpenSSL 1.0.2, but from the dump i see that the Apache distribution is linked with OpenSSL
1.1.0. It is likely to cause issues in completely unrelated parts. So please check and ensure, that
both PHP and Apache are linked with the same OpenSSL version. It were preferable to use teh official
PHP builds and httpd from apachelounge.com. Please also ensule that the runtime is same, too.
Another point is - PHP below 7.2 has issues with the thread safety, which was fixed in 7.2 and
won't be backported. It might make sense, now that 7.2 is out and you use PHP as Apache module,
to upgrade it.
On my side, i've also tested your snippet with PHP as Apache module under quite some stress
scenarios like "ab -c 4", but still couldn't able to get on the crash :(
Thanks.
------------------------------------------------------------------------
[2018-01-22 05:46:53] zhang_xiaobao at venustech dot com dot cn
I hava already sent the process dump information to you by email(1486805345@qq.com),please check it.
------------------------------------------------------------------------
[2018-01-22 05:31:35] zhang_xiaobao at venustech dot com dot cn
Because of the work mailbox has an attachment size limit,I will send process dump information for
you through my other mailbox(1486805345@qq.com).
------------------------------------------------------------------------
[2018-01-20 19:29:38] ab@php.net
Thanks for the report. I currently don't reproduce any crash with your code. Could you please
provide a corresponding backtrace and/or crash dump? Modules are only freed at the process exit,
mpm_winnt is only one child per server. Is that about mpm_winnt or fcgi?
Disregarding the possible crash, I'd not see this as a security issue.
Thanks.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=75840
--
Edit this bug report at https://bugs.php.net/bug.php?id=75840&edit=1