Re: Fwd: CHINANSL Security Advisory(CSA-200011)

From: Date: Sun, 10 Dec 2000 06:21:30 +0000
Subject: Re: Fwd: CHINANSL Security Advisory(CSA-200011)
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-40730@lists.php.net to get a copy of this message
I can tell you that this is not a bug on Linux or Solaris 2.6, using Apache 1.3.12 or 1.3.14. I also tried: http://localhost/index.php%2f../..%2fusr/local/apache/conf/httpd.conf That didn't work either. On Sun, 10 Dec 2000, Zeev Suraski wrote the following to php-dev@lists.php.net : > Has anybody taken a look at it? > > Zeev > > >Delivered-To: alias-zend-zeev@ZEND.COM > >Approved-By: aleph1@SECURITYFOCUS.COM > >Delivered-To: bugtraq@lists.securityfocus.com > >Delivered-To: bugtraq@securityfocus.com > >X-Mailer: Security Focus > >Date: Wed, 6 Dec 2000 07:47:00 -0000 > >Reply-To: webmaster@CHINANSL.COM > >Sender: Bugtraq List <BUGTRAQ@SECURITYFOCUS.COM> > >From: china nsl <webmaster@CHINANSL.COM> > >Subject: CHINANSL Security Advisory(CSA-200011) > >To: BUGTRAQ@SECURITYFOCUS.COM > > > > > >CHINANSL Security Advisory(CSA-200011) > > > >Topic: PHP AND APACHE Vulnerability > > > >Release Date£º Dec 6, 2000 > > > >Affected system: > >============ > > > >APACHE WEB SERVER 1.3 > >¡¡¡¡- Microsoft Windows NT 4.0 > >¡¡¡¡- Microsoft Windows 2000 > >Impact: > >====== > > > >CHINANSL security team has found a security > >problem in Apache web server > >where using php3. Exploitation of this vulnerability, A > >malicious user > >can access the content of file in the machine where > >Apache web server > >is runing. > > > >Description£º > >========= > > > >For example (Windows 2000 + Apache 1.3.6 + > >PHP3): > > > >http://taget/index.php3.%5c../..%5cconf/httpd.conf > >You will get the httpd.conf file. > > > >Exploit: > >===== > > > >run arbitrary command : > > > >http://taget/index.php3.%5c../..%5cconf/httpd.conf > >You will get the httpd.conf file. > > > > > >Solution: > >======= > > > >None > > > >DISCLAIMS: > >======== > >THE INFORMATION PROVIDED IS RELEASED BY > >CHINANSL "AS IS" WITHOUT WARRANTY OF ANY > >KIND. CHINANSL DISCLAIMS ALL WARRANTIES, > >EITHER EXPRESS OR IMPLIED, EXCEPT FOR > >THE WARRANTIES OF MERCHANTABILITY. IN NO > >EVENTSHALL CHINANSL BE LIABLE FOR ANY > >DAMAGES WHATSOEVER INCLUDING DIRECT, > >INDIRECT, INCIDENTAL,CONSEQUENTIAL, LOSS > >OF BUSINESS PROFITS OR SPECIAL DAMAGES, > >EVEN IF CHINANSL HAS BEEN ADVISED OF THE > >POSSIBILITY OF SUCH DAMAGES. DISTRIBUTION > >OR REPRODUTION OF THE INFORMATION IS > >PROVIDED THAT THE ADVISORY IS NOT > >MODIFIED IN ANY WAY. > > > >Copyright 1999-2000 CHINANSL. All Rights > >Reserved. Terms of use. > > > >CHINANSL Security Team (http://www.chinansl.com) > > -- > Zeev Suraski <zeev@zend.com> > CTO, Zend Technologies Ltd. http://www.zend.com/ > > >

« previous php.dev (#40730) next »