Bug #77932 [Opn]: Source Disclosure Vulnerability
| From: | nurudin dot imsirovic at gmail dot com | Date: | Tue, 23 Apr 2019 15:47:29 +0000 |
| Subject: | Bug #77932 [Opn]: Source Disclosure Vulnerability | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-220573@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77932&edit=1
ID: 77932
User updated by: nurudin dot imsirovic at gmail dot com
Reported by: nurudin dot imsirovic at gmail dot com
Summary: Source Disclosure Vulnerability
Status: Open
Type: Bug
Package: Built-in web server
Operating System: Windows, Linux
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
Description:
------------
The test script contains a HTML form that will send the parameter POST key to the php file where
backend script and the form is located.
If the key matches the secret variable It will print Logged in, otherwise It'll print
Permission denied.
The only way to access this "secret" variable is to scan the web server for
vulnerabilities, but there is a way with the PHP built-in webserver.
Lets say the location of the script is located at /admin.php and only the Administrator of that page
knows the secret, which is embedded into the PHP script.
If he is port forwarding the PHP Built-in server to the public world then we are in a position to
actually see the source code, but of course this doesn't have to be public it can be a user on
a local network running the server without firewall rules to block outsiders.
So, we have /admin.php on the server but If we open a new tab and replace it with /admin.PHP the
server outputs the source code of the script and thus giving us the ability to see whats inside
$secret variable.
Test script:
---------------
<form action="" method="POST">
<input name="key">
<input type="submit">
</form>
<?php
$secret = '0x000000f'; // random key
if ($_POST) {
$key = $_POST['key'];
if ($key == $secret) {
printf("Logged in!");
} else {
printf("Permission denied.");
}
}
?>
Previous Comments:
------------------------------------------------------------------------
[2019-04-23 15:46:59] nurudin dot imsirovic at gmail dot com
Description:
------------
The test script contains a HTML form that will send the parameter POST key to the php file where
backend script and the form is located.
If the key matches the secret variable It will print Logged in, otherwise It'll print
Permission denied.
The only way to access this "secret" variable is to scan the web server for
vulnerabilities, but there is a way with the PHP built-in webserver.
Lets say the location of the script is located at /admin.php and only the Administrator of that page
knows the secret, which is embedded into the PHP script.
If he is port forwarding the PHP Built-in server to the public world then we are in a position to
actually see the source code, but of course this doesn't have to be public it can be a user on
a local network running the server without firewall rules to block outsiders.
So, we have /admin.php on the server but If we open a new tab and replace it with /admin.PHP the
server outputs the source code of the script and thus giving us the ability to see whats inside
$secret variable.
Test script:
---------------
<form action="" method="POST">
<input name="key">
<input type="submit">
</form>
<?php
$secret = '0x000000f'; // random key
if ($_POST) {
$key = $_POST['key'];
if ($key == $secret) {
printf("Logged in!");
} else {
printf("Permission denied.");
}
}
?>
------------------------------------------------------------------------
[2019-04-23 15:42:07] nurudin dot imsirovic at gmail dot com
Description:
------------
The test script contains a HTML form that will send the parameter POST key to the php file where
backend script and the form is located.
If the key matches the secret variable It will print Logged in, otherwise It'll print
Permission denied.
The only way to access this "secret" variable is to scan the web server for
vulnerabilities, but there is a way with the PHP built-in webserver.
Lets say the location of the script is located at /admin.php and only the Administrator of that page
knows the secret, which is embedded into the PHP script.
If he is port forwarding the PHP Built-in server to the public world then we are in a position to
actually see the source code, but of course this doesn't have to be public it can be a user on
a local network running the server without firewall rules to block outsiders.
So, we have /admin.php on the server but If we open a new tab and replace it with /admin.PHP the
server outputs the source code of the script and thus giving us the ability to see whats inside
$secret variable.
Test script:
---------------
<form action="">
<input name="key">
<input type="submit">
</form>
<?php
$secret = '0x000000f'; // random key
$key = $_POST['key'];
if (isset($key)) {
if ($key !== $secret) {
pritnf("Logged in!");
} else {
printf("Permission denied.");
}
}
?>
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=77932&edit=1