Req #79324 [Com]: Alternative to safe_mode_protected_env_vars
| From: | bugreports at gmail dot com | Date: | Sun, 01 Mar 2020 17:52:22 +0000 |
| Subject: | Req #79324 [Com]: Alternative to safe_mode_protected_env_vars | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-225821@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=79324&edit=1
ID: 79324
Comment by: bugreports at gmail dot com
Reported by: diego dot blanco at treitos dot com
Summary: Alternative to safe_mode_protected_env_vars
Status: Open
Type: Feature/Change Request
Package: Scripting Engine problem
PHP Version: 7.4.3
Block user comment: N
Private report: N
New Comment:
i don't know any software which don't support smtp via phpmailer and mail() is in
disabled_functions() here since 2002 which is 18 years now
Previous Comments:
------------------------------------------------------------------------
[2020-03-01 17:49:49] diego dot blanco at treitos dot com
Thank you for your clarification Nikic. I just wanted to give more information about the problem so
the implications are better understood. If you consider this is the right category, that is totally
fine for me.
Regarding disabling mail() for a secure setup, although I agree it would be safer, it is an expected
feature for most of legit users so disabling it is not as an easy choice as disabling shell_exec().
For this reason it is usually enabled and the use of LD_PRELOAD to bypass restrictions is well known
among web hackers (both white and black hats)
------------------------------------------------------------------------
[2020-03-01 17:32:08] nikic@php.net
To clarify, the "Security" category is for bugs that need to be kept private until the fix
has been released. The classification change is not supposed to imply that there is no relation to
security here, just that it doesn't need to be confidential.
------------------------------------------------------------------------
[2020-03-01 17:29:50] bugreports at gmail dot com
when your setup is able to start a suid binary like sendmail and mail() is not disabled you have
much more things to worry
again: in a *sensibke* setup with security in mind there are nol libraries loaded and binaries
executed at the runtime of a script, all the php extensions and tehir libraries are lareay loaded
long before you can call setenv()
------------------------------------------------------------------------
[2020-03-01 17:22:56] diego dot blanco at treitos dot com
You can use "strace" to see what external functions some PHP functions. For example the
"mail" function calls "geteuid". So you can code a library that reimplements
that function (i.e. "geteuid") and do whatever you want. Then you use LD_PRELOAD to load
your custom library and then call the PHP function (i.e. "mail") so it will trigger your
custom code.
You have a good example here using these very same functions: https://github.com/0verl0ad/sifilis-PoC/
------------------------------------------------------------------------
[2020-03-01 17:10:31] bugreports at gmail dot com
and how is that user supposed to load any binary code in a sensible setup with dl() not enabled to
begin with? LD_PRELOAD in the middle of the process is completly meaningless
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=79324
--
Edit this bug report at https://bugs.php.net/bug.php?id=79324&edit=1