Re: Pretty mammoth security issue with safe_mode_exec

From: Date: Fri, 05 Jan 2001 13:03:54 +0000
Subject: Re: Pretty mammoth security issue with safe_mode_exec
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-43038@lists.php.net to get a copy of this message
Woops, best ignore this patch. The bug is real, but this (untested :) patch is fubar adamw ----- Original Message ----- From: "Adam Wright" <adam@elysium.ltd.uk> To: "PHP Development" <php-dev@lists.php.net> Cc: <zeev@zend.com> Sent: Friday, January 05, 2001 12:11 PM Subject: [PHP-DEV] Pretty mammoth security issue with safe_mode_exec > If you have safe mode enabled, and have a safe mode exec directory, here's > how you can execute binarys outside of your safe mode exec directory! > > Normally... > > system("../../../../../bin/cp blah blip"); > > would fail (as .. is blocked in _Exec (standard/exec.c) > > However... > > system("\.\./\.\./\.\./\.\./\.\./bin/cp blah blip"); > > will work fine! This is because the .. check was performed before the > php_escape_shell_cmd in exec.c! > > --We fixed it, and our PHP *still* compiles :) > > (untested patch for exec.c attached) > > adamw > adam@elysium.ltd.uk > > > > ---------------------------------------------------------------------------- ---- > -- > PHP Development Mailing List <http://www.php.net/> > To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net > For additional commands, e-mail: php-dev-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net

« previous php.dev (#43038) next »