Sec Bug->Bug #81339 [Opn]: PHP source code exposed on Windows

From: Date: Sat, 07 Aug 2021 14:05:11 +0000
Subject: Sec Bug->Bug #81339 [Opn]: PHP source code exposed on Windows
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-235658@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81339&edit=1 ID: 81339 Updated by: cmb@php.net Reported by: phith0n dot ph2f at gmail dot com Summary: PHP source code exposed on Windows Status: Open -Type: Security +Type: Bug Package: Built-in web server Operating System: Windows PHP Version: 8.0.9 -Assigned To: +Assigned To: cmb Block user comment: N Private report: Y New Comment: I don't see an immediate security issue in php-src. However, there are inconsistencies regarding the default and alternate file and dir streams. While file_exists() and friends report any such stream as not accessible (i.e. they return false), and realpath() returns false as well, reading, writing and statting these streams is fully supported. copy($filename) (only copies the file's default stream) and move($filename) (copies the file with all streams), behave as expected. Furthermore, pathinfo() and friends regard the suffix as part of the file extension, what is not really correct, and *might* cause issues in userland code, which is not aware of NTFS streams. Disabling support for the streams would solve all that, but besides the obvious BC break, would also remove a potentially desired feature. So I think, we should prominently document this issue, and maybe fix the issue regarding the built-in Webserver. Previous Comments: ------------------------------------------------------------------------ [2021-08-07 10:44:40] cmb@php.net Since the built-in Webserver is for *development* purposes only, exposing the source code is not a vulnerability by definition. However, that stream stuff might open other vulnerabilities, so I'm tentatively switching to sec bug while this is being investigated closer. Thank you for reporting this issue! ------------------------------------------------------------------------ [2021-08-07 10:22:34] phith0n dot ph2f at gmail dot com Description: ------------ I am using the PHP built-in server as the development web server on Windows. Recently I found a bug, sometimes a vulnerability, which is able to expose the PHP scripts' source code in the web folder. NTFS stream is supported on Windows, reference to this document: <https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-fscc/c54dec26-1551-4d3a-a0ea-4fa40f848eb3>. So use info.php::$DATA to open and read the file info.php is valid, which is bypass the extension dispatch in built-in web server: ```c if (client->request.ext_len != 3 || (ext[0] != 'p' && ext[0] != 'P') || (ext[1] != 'h' && ext[1] != 'H') || (ext[2] != 'p' && ext[2] != 'P') || !client->request.path_translated) { is_static_file = 1; } ``` Some related bugs are: - https://bugs.php.net/77932 - https://bugs.php.net/71559 Test script: --------------- Run PHP built-in server on Windows NTFS filesystem: ``` php -S localhost:9090 ``` Put a PHP script info.php in the web folder: ``` <?php phpinfo(); ``` Browse the http://localhost:9090/info.php::$DATA` from browser or CURL. Expected result: ---------------- A "404 not found" error is raised. Actual result: -------------- Source code of info.php is exposed: <https://imgur.com/G9tBTHy> ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=81339&edit=1

« previous php.bugs (#235658) next »