Edit report at https://bugs.php.net/bug.php?id=75840&edit=1
ID: 75840
Updated by: php-bugs@lists.php.net
Reported by: zhang_xiaobao at venustech dot com dot cn
Summary: when i load COM('WScript.shell') and call
exec('cmd.exe /c whoami') to execute
-Status: Feedback
+Status: No Feedback
Type: Bug
Package: COM related
Operating System: windows
PHP Version: 7.0.27
Private report: N
New Comment:
No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Re-Opened". Thank you.
Previous Comments:
------------------------------------------------------------------------
[2018-07-07 16:04:10] ab@php.net
Any news on this?
Thanks.
------------------------------------------------------------------------
[2018-01-23 02:42:33] zhang_xiaobao at venustech dot com dot cn
Thank you for your suggestion,I'll retest this vulnerability later on your advice and send you
a document on the details of the vulnerability.
------------------------------------------------------------------------
[2018-01-22 11:57:16] ab@php.net
Thanks for sending the crash dump. Unfortunately i could only see a few stack frames, because the
libhttpd.dll is missing the debug symbols and they're not provided by XAMPP, too. Eg.
> libhttpd.dll!_ap_run_generate_log_id@12() + 7350 bytes Unknown No symbols loaded.
[Frames below may be incorrect and/or missing, no symbols loaded for libhttpd.dll] Annotated
Frame
libhttpd.dll!_ap_signal_parent@4() + 7799 bytes Unknown No symbols loaded.
libhttpd.dll!_ap_run_mpm@12() + 43 bytes Unknown No symbols loaded.
httpd.exe!OPENSSL_Applink() + 2950 bytes Unknown No symbols loaded.
Please also note, that the lack of debug symbols is a usual thing, if no official builds are used.
From the code flow, the command execution would normally block until the command has finished. Every
thread has it's own structures, that would be destroyed separately.
However one guess that i have is about OpenSSL. The report is about 7.0.27 which we officially link
with OpenSSL 1.0.2, but from the dump i see that the Apache distribution is linked with OpenSSL
1.1.0. It is likely to cause issues in completely unrelated parts. So please check and ensure, that
both PHP and Apache are linked with the same OpenSSL version. It were preferable to use teh official
PHP builds and httpd from apachelounge.com. Please also ensule that the runtime is same, too.
Another point is - PHP below 7.2 has issues with the thread safety, which was fixed in 7.2 and
won't be backported. It might make sense, now that 7.2 is out and you use PHP as Apache module,
to upgrade it.
On my side, i've also tested your snippet with PHP as Apache module under quite some stress
scenarios like "ab -c 4", but still couldn't able to get on the crash :(
Thanks.
------------------------------------------------------------------------
[2018-01-22 05:46:53] zhang_xiaobao at venustech dot com dot cn
I hava already sent the process dump information to you by email(1486805345@qq.com),please check it.
------------------------------------------------------------------------
[2018-01-22 05:31:35] zhang_xiaobao at venustech dot com dot cn
Because of the work mailbox has an attachment size limit,I will send process dump information for
you through my other mailbox(1486805345@qq.com).
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=75840
--
Edit this bug report at https://bugs.php.net/bug.php?id=75840&edit=1