Bug #77932 [NEW]: Source Disclosure Vulnerability
| From: | nurudin dot imsirovic at gmail dot com | Date: | Tue, 23 Apr 2019 15:42:07 +0000 |
| Subject: | Bug #77932 [NEW]: Source Disclosure Vulnerability | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-220571@lists.php.net to get a copy of this message | ||
From: nurudin dot imsirovic at gmail dot com
Operating system: Windows, Linux
PHP version: Irrelevant
Package: Built-in web server
Bug Type: Bug
Bug description:Source Disclosure Vulnerability
Description:
------------
The test script contains a HTML form that will send the parameter POST
key to the php file where backend script and the form is located.
If the key matches the secret variable It will print Logged in,
otherwise It'll print Permission denied.
The only way to access this "secret" variable is to scan the web server
for vulnerabilities, but there is a way with the PHP built-in
webserver.
Lets say the location of the script is located at /admin.php and only
the Administrator of that page knows the secret, which is embedded into
the PHP script.
If he is port forwarding the PHP Built-in server to the public world
then we are in a position to actually see the source code, but of course
this doesn't have to be public it can be a user on a local network
running the server without firewall rules to block outsiders.
So, we have /admin.php on the server but If we open a new tab and
replace it with /admin.PHP the server outputs the source code of the
script and thus giving us the ability to see whats inside $secret
variable.
Test script:
---------------
<form action="">
<input name="key">
<input type="submit">
</form>
<?php
$secret = '0x000000f'; // random key
$key = $_POST['key'];
if (isset($key)) {
if ($key !== $secret) {
pritnf("Logged in!");
} else {
printf("Permission denied.");
}
}
?>
--
Edit bug report at https://bugs.php.net/bug.php?id=77932&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=77932&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=77932&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=77932&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=77932&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=77932&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=77932&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=77932&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=77932&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=77932&r=support
Expected behavior: https://bugs.php.net/fix.php?id=77932&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=77932&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=77932&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=77932&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=77932&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=77932&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=77932&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=77932&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=77932&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=77932&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=77932&r=mysqlcfg