Req #79324 [Opn]: Alternative to safe_mode_protected_env_vars
| From: | nikic@php.net | Date: | Sun, 01 Mar 2020 17:32:08 +0000 |
| Subject: | Req #79324 [Opn]: Alternative to safe_mode_protected_env_vars | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-225819@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=79324&edit=1
ID: 79324
Updated by: nikic@php.net
Reported by: diego dot blanco at treitos dot com
Summary: Alternative to safe_mode_protected_env_vars
Status: Open
Type: Feature/Change Request
Package: Scripting Engine problem
PHP Version: 7.4.3
Block user comment: N
Private report: N
New Comment:
To clarify, the "Security" category is for bugs that need to be kept private until the fix
has been released. The classification change is not supposed to imply that there is no relation to
security here, just that it doesn't need to be confidential.
Previous Comments:
------------------------------------------------------------------------
[2020-03-01 17:29:50] bugreports at gmail dot com
when your setup is able to start a suid binary like sendmail and mail() is not disabled you have
much more things to worry
again: in a *sensibke* setup with security in mind there are nol libraries loaded and binaries
executed at the runtime of a script, all the php extensions and tehir libraries are lareay loaded
long before you can call setenv()
------------------------------------------------------------------------
[2020-03-01 17:22:56] diego dot blanco at treitos dot com
You can use "strace" to see what external functions some PHP functions. For example the
"mail" function calls "geteuid". So you can code a library that reimplements
that function (i.e. "geteuid") and do whatever you want. Then you use LD_PRELOAD to load
your custom library and then call the PHP function (i.e. "mail") so it will trigger your
custom code.
You have a good example here using these very same functions: https://github.com/0verl0ad/sifilis-PoC/
------------------------------------------------------------------------
[2020-03-01 17:10:31] bugreports at gmail dot com
and how is that user supposed to load any binary code in a sensible setup with dl() not enabled to
begin with? LD_PRELOAD in the middle of the process is completly meaningless
------------------------------------------------------------------------
[2020-03-01 17:06:56] diego dot blanco at treitos dot com
I see that the type was changed from Security to a "Feature Request". I am not saying that
this change is wrong but I'd like to provide more information to describe why this has an
important security impact.
It is common to add some security measures when installing a PHP environment. Things like
"open_basedir", "disable_functions", etc. This way if a website is compromised
you can limit the impact in other websites or services in the same server.
With the current PHP configuration options it is not possible to prevent users from setting
environment variables like LD_PRELOAD. Due to this a user can upload a custom library and use
LD_PRELOAD to execute code from that library that will effectively bypass any of the previous
restrictions.
In other words, a user that can execute custom PHP code can easily bypass restrictions like
"open_basedir" or "disabled_functions" because systems administrators do not
have a way to prevent users from setting LD_PRELOAD (other than disabling "putenv"
function).
I think this has a significant impact in security.
------------------------------------------------------------------------
[2020-02-29 18:45:25] diego dot blanco at treitos dot com
Description:
------------
In old versions of PHP it was possible to prevent end users to set sensitive environment variables
such as LD_PRELOAD or LD_LIBRARY_PATH using safe_mode_protected_env_vars.
After safe_mod was deprecated I cannot find any way of doing this. The only workaround is to
absolutely disable the putenv function.
Is this feature hidden anywhere? If so, it might be good to update the documentation and add links
in this page: https://www.php.net/manual/en/ini.sect.safe-mode.php#ini.safe-mode-protected-env-vars
If it is not, I think this should be implemented.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=79324&edit=1