Bug #77932 [Opn->Ver]: File extensions are case-sensitive
| From: | cmb@php.net | Date: | Mon, 27 Jul 2020 08:59:19 +0000 |
| Subject: | Bug #77932 [Opn->Ver]: File extensions are case-sensitive | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-228234@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77932&edit=1
ID: 77932
Updated by: cmb@php.net
Reported by: nurudin dot imsirovic at gmail dot com
Summary: File extensions are case-sensitive
-Status: Open
+Status: Verified
Type: Bug
Package: Built-in web server
Operating System: Windows, Linux
PHP Version: Irrelevant
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
> Yes but the only file contained inside the folder is admin.php,
> no admin.PHP just admin.php but the built-in server doesn't
> execute .PHP as a script but rather proceeds to output the source
> code.
That only happens with case-insensitive file systems, though.
Previous Comments:
------------------------------------------------------------------------
[2019-04-23 22:58:07] nurudin dot imsirovic at gmail dot com
Yes but the only file contained inside the folder is admin.php, no admin.PHP just admin.php but the
built-in server doesn't execute .PHP as a script but rather proceeds to output the source code.
------------------------------------------------------------------------
[2019-04-23 21:07:33] requinix@php.net
https://www.php.net/manual/en/features.commandline.webserver.php
The very first thing on the page:
> Warning
> This web server was designed to aid application development. It may also be useful for testing
> purposes or for
> application demonstrations that are run in controlled environments. It is not intended to be a
> full-featured web
> server. It should not be used on a public network.
With that said, I see no reason why the server couldn't recognize "php"
case-insensitively, and if it does then it should recognize the other extensions insensitively too.
------------------------------------------------------------------------
[2019-04-23 17:03:50] spam2 at rhsoft dot net
> If he is port forwarding the PHP Built-in server to the public world
than he is a fool because the builtin websevrer is for development only and MUST NOT be exposed to
the internet
------------------------------------------------------------------------
[2019-04-23 15:47:29] nurudin dot imsirovic at gmail dot com
Description:
------------
The test script contains a HTML form that will send the parameter POST key to the php file where
backend script and the form is located.
If the key matches the secret variable It will print Logged in, otherwise It'll print
Permission denied.
The only way to access this "secret" variable is to scan the web server for
vulnerabilities, but there is a way with the PHP built-in webserver.
Lets say the location of the script is located at /admin.php and only the Administrator of that page
knows the secret, which is embedded into the PHP script.
If he is port forwarding the PHP Built-in server to the public world then we are in a position to
actually see the source code, but of course this doesn't have to be public it can be a user on
a local network running the server without firewall rules to block outsiders.
So, we have /admin.php on the server but If we open a new tab and replace it with /admin.PHP the
server outputs the source code of the script and thus giving us the ability to see whats inside
$secret variable.
Test script:
---------------
<form action="" method="POST">
<input name="key">
<input type="submit">
</form>
<?php
$secret = '0x000000f'; // random key
if ($_POST) {
$key = $_POST['key'];
if ($key == $secret) {
printf("Logged in!");
} else {
printf("Permission denied.");
}
}
?>
------------------------------------------------------------------------
[2019-04-23 15:46:59] nurudin dot imsirovic at gmail dot com
Description:
------------
The test script contains a HTML form that will send the parameter POST key to the php file where
backend script and the form is located.
If the key matches the secret variable It will print Logged in, otherwise It'll print
Permission denied.
The only way to access this "secret" variable is to scan the web server for
vulnerabilities, but there is a way with the PHP built-in webserver.
Lets say the location of the script is located at /admin.php and only the Administrator of that page
knows the secret, which is embedded into the PHP script.
If he is port forwarding the PHP Built-in server to the public world then we are in a position to
actually see the source code, but of course this doesn't have to be public it can be a user on
a local network running the server without firewall rules to block outsiders.
So, we have /admin.php on the server but If we open a new tab and replace it with /admin.PHP the
server outputs the source code of the script and thus giving us the ability to see whats inside
$secret variable.
Test script:
---------------
<form action="" method="POST">
<input name="key">
<input type="submit">
</form>
<?php
$secret = '0x000000f'; // random key
if ($_POST) {
$key = $_POST['key'];
if ($key == $secret) {
printf("Logged in!");
} else {
printf("Permission denied.");
}
}
?>
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=77932
--
Edit this bug report at https://bugs.php.net/bug.php?id=77932&edit=1