Bug #78047 [Com]: [DoS] Segmentation fault through HTTP Requests
| From: | spam2 at rhsoft dot net | Date: | Wed, 22 May 2019 08:12:38 +0000 |
| Subject: | Bug #78047 [Com]: [DoS] Segmentation fault through HTTP Requests | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-220939@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78047&edit=1
ID: 78047
Comment by: spam2 at rhsoft dot net
Reported by: michele dot cisternino at protonmail dot com
Summary: [DoS] Segmentation fault through HTTP Requests
Status: Open
Type: Bug
Package: Built-in web server
Operating System: Linux
PHP Version: 7.3Git-2019-05-21 (snap)
Block user comment: N
Private report: N
New Comment:
> can crash all the public instances of the built-in server
hopefully and then the people maybe read the first red box at https://www.php.net/manual/en/features.commandline.webserver.php
Previous Comments:
------------------------------------------------------------------------
[2019-05-22 07:57:44] michele dot cisternino at protonmail dot com
I disagree, respectfully.
A malicious user, thanks to this exploit, can crash all the public instances of the built-in server
(around 2.000, in my search).
Anyway, if you don't agree, I can disclose it (you also switched the status from Private to
Public), so we can see what the hacking community think about it.
Have a nice day :)
------------------------------------------------------------------------
[2019-05-22 07:40:34] cmb@php.net
To clarify: the built-in web server *can* of course be connected
to a public network; it is, however, not supposed to[1]. Therefore
we do not consider any issues related to the built-in web server
to be security issues.
[1] <https://www.php.net/manual/en/features.commandline.webserver.php>
------------------------------------------------------------------------
[2019-05-21 18:35:46] michele dot cisternino at protonmail dot com
Sorry for the late reply.
Yes, the server is usually used for testing purposes, but it can be esposed to the internet as well.
You can launch a simple query on Shodan to find multiple instances of the built-in PHP server
exposed.
An attacker could write a script that launch a request to the Shodan's API, get a list of
vulnerable instances and DoS them all iteratively.
Moreover, In my daily pentest-job, I found this kind of Server not exposed to the internet, but used
internally by the companies.
An attacker, thanks to the exploit I wrote, could cause a continuous DoS.
Moreover, as I already said, the vulnerability could be further investigated to upgrade it to an
RCE.
I hope you understand the criticality of the vulnerability.
------------------------------------------------------------------------
[2019-05-21 17:46:40] cmb@php.net
> The vulnerability could be exploited by an attacker [â¦]
No, it can not, because the built-in webserver is for
*development* purposes only.
------------------------------------------------------------------------
[2019-05-21 15:18:51] michele dot cisternino at protonmail dot com
The exploit consists in sending HTTP requests in the following order:
1 - Request the base URL
2 - Request a valid file on the server
3 - Request a non-existent file on the server
4 - Request the base URL
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=78047
--
Edit this bug report at https://bugs.php.net/bug.php?id=78047&edit=1