Bug #77932 [Opn->Ver]: File extensions are case-sensitive

From: Date: Mon, 27 Jul 2020 08:59:19 +0000
Subject: Bug #77932 [Opn->Ver]: File extensions are case-sensitive
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-228234@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77932&edit=1 ID: 77932 Updated by: cmb@php.net Reported by: nurudin dot imsirovic at gmail dot com Summary: File extensions are case-sensitive -Status: Open +Status: Verified Type: Bug Package: Built-in web server Operating System: Windows, Linux PHP Version: Irrelevant -Assigned To: +Assigned To: cmb Block user comment: N Private report: N New Comment: > Yes but the only file contained inside the folder is admin.php, > no admin.PHP just admin.php but the built-in server doesn't > execute .PHP as a script but rather proceeds to output the source > code. That only happens with case-insensitive file systems, though. Previous Comments: ------------------------------------------------------------------------ [2019-04-23 22:58:07] nurudin dot imsirovic at gmail dot com Yes but the only file contained inside the folder is admin.php, no admin.PHP just admin.php but the built-in server doesn't execute .PHP as a script but rather proceeds to output the source code. ------------------------------------------------------------------------ [2019-04-23 21:07:33] requinix@php.net https://www.php.net/manual/en/features.commandline.webserver.php The very first thing on the page: > Warning > This web server was designed to aid application development. It may also be useful for testing > purposes or for > application demonstrations that are run in controlled environments. It is not intended to be a > full-featured web > server. It should not be used on a public network. With that said, I see no reason why the server couldn't recognize "php" case-insensitively, and if it does then it should recognize the other extensions insensitively too. ------------------------------------------------------------------------ [2019-04-23 17:03:50] spam2 at rhsoft dot net > If he is port forwarding the PHP Built-in server to the public world than he is a fool because the builtin websevrer is for development only and MUST NOT be exposed to the internet ------------------------------------------------------------------------ [2019-04-23 15:47:29] nurudin dot imsirovic at gmail dot com Description: ------------ The test script contains a HTML form that will send the parameter POST key to the php file where backend script and the form is located. If the key matches the secret variable It will print Logged in, otherwise It'll print Permission denied. The only way to access this "secret" variable is to scan the web server for vulnerabilities, but there is a way with the PHP built-in webserver. Lets say the location of the script is located at /admin.php and only the Administrator of that page knows the secret, which is embedded into the PHP script. If he is port forwarding the PHP Built-in server to the public world then we are in a position to actually see the source code, but of course this doesn't have to be public it can be a user on a local network running the server without firewall rules to block outsiders. So, we have /admin.php on the server but If we open a new tab and replace it with /admin.PHP the server outputs the source code of the script and thus giving us the ability to see whats inside $secret variable. Test script: --------------- <form action="" method="POST"> <input name="key"> <input type="submit"> </form> <?php $secret = '0x000000f'; // random key if ($_POST) { $key = $_POST['key']; if ($key == $secret) { printf("Logged in!"); } else { printf("Permission denied."); } } ?> ------------------------------------------------------------------------ [2019-04-23 15:46:59] nurudin dot imsirovic at gmail dot com Description: ------------ The test script contains a HTML form that will send the parameter POST key to the php file where backend script and the form is located. If the key matches the secret variable It will print Logged in, otherwise It'll print Permission denied. The only way to access this "secret" variable is to scan the web server for vulnerabilities, but there is a way with the PHP built-in webserver. Lets say the location of the script is located at /admin.php and only the Administrator of that page knows the secret, which is embedded into the PHP script. If he is port forwarding the PHP Built-in server to the public world then we are in a position to actually see the source code, but of course this doesn't have to be public it can be a user on a local network running the server without firewall rules to block outsiders. So, we have /admin.php on the server but If we open a new tab and replace it with /admin.PHP the server outputs the source code of the script and thus giving us the ability to see whats inside $secret variable. Test script: --------------- <form action="" method="POST"> <input name="key"> <input type="submit"> </form> <?php $secret = '0x000000f'; // random key if ($_POST) { $key = $_POST['key']; if ($key == $secret) { printf("Logged in!"); } else { printf("Permission denied."); } } ?> ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=77932 -- Edit this bug report at https://bugs.php.net/bug.php?id=77932&edit=1

« previous php.bugs (#228234) next »