Req #79324 [Opn]: Alternative to safe_mode_protected_env_vars

From: Date: Sun, 01 Mar 2020 17:06:56 +0000
Subject: Req #79324 [Opn]: Alternative to safe_mode_protected_env_vars
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-225815@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79324&edit=1 ID: 79324 User updated by: diego dot blanco at treitos dot com Reported by: diego dot blanco at treitos dot com Summary: Alternative to safe_mode_protected_env_vars Status: Open Type: Feature/Change Request Package: Scripting Engine problem PHP Version: 7.4.3 Block user comment: N Private report: N New Comment: I see that the type was changed from Security to a "Feature Request". I am not saying that this change is wrong but I'd like to provide more information to describe why this has an important security impact. It is common to add some security measures when installing a PHP environment. Things like "open_basedir", "disable_functions", etc. This way if a website is compromised you can limit the impact in other websites or services in the same server. With the current PHP configuration options it is not possible to prevent users from setting environment variables like LD_PRELOAD. Due to this a user can upload a custom library and use LD_PRELOAD to execute code from that library that will effectively bypass any of the previous restrictions. In other words, a user that can execute custom PHP code can easily bypass restrictions like "open_basedir" or "disabled_functions" because systems administrators do not have a way to prevent users from setting LD_PRELOAD (other than disabling "putenv" function). I think this has a significant impact in security. Previous Comments: ------------------------------------------------------------------------ [2020-02-29 18:45:25] diego dot blanco at treitos dot com Description: ------------ In old versions of PHP it was possible to prevent end users to set sensitive environment variables such as LD_PRELOAD or LD_LIBRARY_PATH using safe_mode_protected_env_vars. After safe_mod was deprecated I cannot find any way of doing this. The only workaround is to absolutely disable the putenv function. Is this feature hidden anywhere? If so, it might be good to update the documentation and add links in this page: https://www.php.net/manual/en/ini.sect.safe-mode.php#ini.safe-mode-protected-env-vars If it is not, I think this should be implemented. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=79324&edit=1

« previous php.bugs (#225815) next »