Bug #75840 [NoF]: when i load COM('WScript.shell') and call exec('cmd.exe /c whoami') to execute
| From: | requinix@php.net | Date: | Fri, 14 Dec 2018 21:07:48 +0000 |
| Subject: | Bug #75840 [NoF]: when i load COM('WScript.shell') and call exec('cmd.exe /c whoami') to execute | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-218457@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75840&edit=1
ID: 75840
Updated by: requinix@php.net
Reported by: zhang_xiaobao at venustech dot com dot cn
Summary: when i load COM('WScript.shell') and call
exec('cmd.exe /c whoami') to execute
Status: No Feedback
Type: Bug
Package: COM related
Operating System: windows
PHP Version: 7.0.27
Block user comment: N
Private report: N
New Comment:
Same question for you: please provide a backtrace or crash dump.
Previous Comments:
------------------------------------------------------------------------
[2018-12-14 21:04:12] david dot soft at yahoo dot com
I am still having this issue on both php.exe and php-cgi.exe on Apache.
Sample code:
$test = new COM('WScript.Shell');
This causes PHP 7.2.9 x64 ZTS to crash.
Any ideas?
------------------------------------------------------------------------
[2018-07-15 04:22:21] php-bugs at lists dot php dot net
No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Re-Opened". Thank you.
------------------------------------------------------------------------
[2018-07-07 16:04:10] ab@php.net
Any news on this?
Thanks.
------------------------------------------------------------------------
[2018-01-23 02:42:33] zhang_xiaobao at venustech dot com dot cn
Thank you for your suggestion,I'll retest this vulnerability later on your advice and send you
a document on the details of the vulnerability.
------------------------------------------------------------------------
[2018-01-22 11:57:16] ab@php.net
Thanks for sending the crash dump. Unfortunately i could only see a few stack frames, because the
libhttpd.dll is missing the debug symbols and they're not provided by XAMPP, too. Eg.
> libhttpd.dll!_ap_run_generate_log_id@12() + 7350 bytes Unknown No symbols loaded.
[Frames below may be incorrect and/or missing, no symbols loaded for libhttpd.dll] Annotated
Frame
libhttpd.dll!_ap_signal_parent@4() + 7799 bytes Unknown No symbols loaded.
libhttpd.dll!_ap_run_mpm@12() + 43 bytes Unknown No symbols loaded.
httpd.exe!OPENSSL_Applink() + 2950 bytes Unknown No symbols loaded.
Please also note, that the lack of debug symbols is a usual thing, if no official builds are used.
From the code flow, the command execution would normally block until the command has finished. Every
thread has it's own structures, that would be destroyed separately.
However one guess that i have is about OpenSSL. The report is about 7.0.27 which we officially link
with OpenSSL 1.0.2, but from the dump i see that the Apache distribution is linked with OpenSSL
1.1.0. It is likely to cause issues in completely unrelated parts. So please check and ensure, that
both PHP and Apache are linked with the same OpenSSL version. It were preferable to use teh official
PHP builds and httpd from apachelounge.com. Please also ensule that the runtime is same, too.
Another point is - PHP below 7.2 has issues with the thread safety, which was fixed in 7.2 and
won't be backported. It might make sense, now that 7.2 is out and you use PHP as Apache module,
to upgrade it.
On my side, i've also tested your snippet with PHP as Apache module under quite some stress
scenarios like "ab -c 4", but still couldn't able to get on the crash :(
Thanks.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=75840
--
Edit this bug report at https://bugs.php.net/bug.php?id=75840&edit=1