Re: Pretty mammoth security issue with safe_mode_exec
| From: | Zeev Suraski | Date: | Fri, 05 Jan 2001 12:42:51 +0000 |
| Subject: | Re: Pretty mammoth security issue with safe_mode_exec | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-43034@lists.php.net to get a copy of this message | ||
At 14:11 5/1/2001, Adam Wright wrote:
If you have safe mode enabled, and have a safe mode exec directory, here's how you can execute binarys outside of your safe mode exec directory! Normally... system("../../../../../bin/cp blah blip"); would fail (as .. is blocked in _Exec (standard/exec.c) However... system("\.\./\.\./\.\./\.\./\.\./bin/cp blah blip"); will work fine! This is because the .. check was performed before the php_escape_shell_cmd in exec.c!That's very very odd, because as far as system() (or any function for that matter) is concerned, ".." and "\.\." is exactly the same thing. At the scanner level, all the way down in the Zend Engine, it converts the bogus "\.\." string (which has illegal escapes) to "..". Are you sure this is the symptom exactly? Zeev -- Zeev Suraski <zeev@zend.com> CTO & co-founder, Zend Technologies Ltd. http://www.zend.com/