Bug #75889 [Opn]: Overloading disk with temporary files
| From: | bukka@php.net | Date: | Fri, 03 Feb 2023 14:11:35 +0000 |
| Subject: | Bug #75889 [Opn]: Overloading disk with temporary files | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-243629@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75889&edit=1
ID: 75889
Updated by: bukka@php.net
Reported by: c dot r dot l dot f at yandex dot ru
Summary: Overloading disk with temporary files
Status: Open
Type: Bug
Package: FPM related
Operating System: Linux
PHP Version: 7.1.13
Block user comment: N
Private report: N
New Comment:
After some investigation of this I found another related private report that shed a bit more light
on this issue. I was not actually able to use this reproducer even with some modifications as nginx
was constantly returning 499. But managed to get a different one:
touch evil_upload; curl -F 'test=@evil_upload' http://localhost:8080/index.php >/dev/null 2>&1
& CPID=$! && echo $CPID && sleep 10 && kill -9 $CPID; rm evil_upload
The private report actually noted that it was due to bail out which I actually fixed as part of https://github.com/php/php-src/commit/3503b1daa265777588b3219b82219a0056675ca0
so the issue is fixed now.
I should say that this was definitely a security issue in my eyes as it is not true that you can
upload files until out of disk space because we have got a limit max_upload_files. Stas probably
didn't realise that the issue is happening even with this limit in place which should never
happen and disk exhaustion is definitely a problem that should be treated as a security issue. So if
you still manage to recreate this or similar issue with file uploads somehow, please report it as a
new security issue.
Previous Comments:
------------------------------------------------------------------------
[2018-02-01 02:21:53] c dot r dot l dot f at yandex dot ru
Yep, I just checked it, it's not reproducible when file_uploads = Off.
------------------------------------------------------------------------
[2018-02-01 02:13:29] stas@php.net
So do I understand correctly the problem does not exist when file uploads are disabled?
------------------------------------------------------------------------
[2018-02-01 02:06:42] c dot r dot l dot f at yandex dot ru
In default installations files uploads is always on, so any host that satisfies the dependencies
(PHP+NGINX) can be attacked.
Please look video PoC:
https://alt3r.eg0.ru/p0c5/12a636fcab5953233706dadacfff3ba8.avi
------------------------------------------------------------------------
[2018-02-01 01:36:58] stas@php.net
Isn't that always the case when uploads are allowed - you can upload files until out of disk
space, absent other limitations like quotas, etc.?
------------------------------------------------------------------------
[2018-02-01 01:01:32] c dot r dot l dot f at yandex dot ru
The problem is that PHP does not delete created temporary files (rfc1867) after connection is
closed.
In the provided scenario, NGINX closes the connection before PHP writes something in it. Judging by
the logs of strace, PHP gets SIGPIPE and for some reasons does not clear temporary files.
Thus, the attacker can upload temporary files while disk space is available. Only reboot or manual
deleting this files will help.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=75889
--
Edit this bug report at https://bugs.php.net/bug.php?id=75889&edit=1