Re: Pretty mammoth security issue with safe_mode_exec
| From: | Adam Wright | Date: | Fri, 05 Jan 2001 13:03:54 +0000 |
| Subject: | Re: Pretty mammoth security issue with safe_mode_exec | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-43038@lists.php.net to get a copy of this message | ||
Woops, best ignore this patch. The bug is real, but this (untested :) patch
is fubar
adamw
----- Original Message -----
From: "Adam Wright" <adam@elysium.ltd.uk>
To: "PHP Development" <php-dev@lists.php.net>
Cc: <zeev@zend.com>
Sent: Friday, January 05, 2001 12:11 PM
Subject: [PHP-DEV] Pretty mammoth security issue with safe_mode_exec
> If you have safe mode enabled, and have a safe mode exec directory, here's
> how you can execute binarys outside of your safe mode exec directory!
>
> Normally...
>
> system("../../../../../bin/cp blah blip");
>
> would fail (as .. is blocked in _Exec (standard/exec.c)
>
> However...
>
> system("\.\./\.\./\.\./\.\./\.\./bin/cp blah blip");
>
> will work fine! This is because the .. check was performed before the
> php_escape_shell_cmd in exec.c!
>
> --We fixed it, and our PHP *still* compiles :)
>
> (untested patch for exec.c attached)
>
> adamw
> adam@elysium.ltd.uk
>
>
>
>
----------------------------------------------------------------------------
----
> --
> PHP Development Mailing List <http://www.php.net/>
> To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net
> For additional commands, e-mail: php-dev-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net