Bug #75044 [Opn->Nab]: Object Injection in PHP's WDDX Serialization

From: Date: Sat, 05 Dec 2020 16:21:49 +0000
Subject: Bug #75044 [Opn->Nab]: Object Injection in PHP's WDDX Serialization
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-230876@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75044&edit=1 ID: 75044 Updated by: cmb@php.net Reported by: taoguangchen at icloud dot com Summary: Object Injection in PHP's WDDX Serialization -Status: Open +Status: Not a bug Type: Bug Package: WDDX related Operating System: * PHP Version: 5.6.31 -Assigned To: +Assigned To: cmb Block user comment: N Private report: N New Comment: Actually, this is not even a bug; the behavior is documented and it is warned against passing untrusted input to that function. Also, the complete WDDX extension is deprecated and unbundled as of PHP 7.4.0. Previous Comments: ------------------------------------------------------------------------ [2017-08-13 19:40:08] cmb@php.net > it would be basically in the same class as unserialize, with > same (none) security guarantees as it seems. Indeed, it is; see <http://news.php.net/php.internals/100183> and <http://svn.php.net/viewvc?view=revision&revision=342852>. ------------------------------------------------------------------------ [2017-08-07 19:50:44] stas@php.net The proposed fix doesn't seem to fix anything in fact, as it's changing serialization, not unserialization, but the question is should we consider this an issue? I.e. if wddx supports live php objects, it would be basically in the same class as unserialize, with same (none) security guarantees as it seems. ------------------------------------------------------------------------ [2017-08-07 10:20:14] taoguangchen at icloud dot com Description: ------------ PoC 1: ``` class ryat { var $hi; function __wakeup() { echo 'hi'; } function __destruct() { echo $this->hi; } } $array = ['php_class_name'=>'ryat', 'hi'=>'ryat']; wddx_deserialize(wddx_serialize_value($array)); ``` PoC 2: ``` ini_set('session.serialize_handler', 'wddx'); session_start(); $array = ['php_class_name'=>'ryat', 'hi'=>'ryat']; $_SESSION['ryat'] = $array; session_decode(session_encode()); class ryat { var $hi; function __wakeup() { echo 'hi'; } function __destruct() { echo $this->hi; } } ``` Fix: ``` static void php_wddx_serialize_array(wddx_packet *packet, zval *arr) { ... if (is_struct) { ent_type = zend_hash_get_current_key_ex(target_hash, &key, &key_len, &idx, 0, NULL); if (ent_type == HASH_KEY_IS_STRING) { + if (!strcmp(key, PHP_CLASS_NAME_VAR)) { + continue; + } php_wddx_serialize_var(packet, *ent, key, key_len TSRMLS_CC); ``` ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=75044&edit=1

« previous php.bugs (#230876) next »