Re: Pretty mammoth security issue with safe_mode_exec

From: Date: Fri, 05 Jan 2001 13:56:33 +0000
Subject: Re: Pretty mammoth security issue with safe_mode_exec
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-43042@lists.php.net to get a copy of this message
Oh, well, actually I was too quick to respond - ".\" is indeed an invalid escape, but PHP treats it as ".\\", and not just ".". I just checked, shells indeed accept \.\. as if it was "..", so the bug is legit. If anybody attempts to fix it - note that \.. and .\. are also possible. Zeev At 14:56 5/1/2001, Adam Wright wrote:
Not to be annoying (well, not entirely), but if \. is parsed out at the lexical level, why does... <? if ("\." == ".") print "Same"; else print "Different"; echo "Different"? adamw ----- Original Message ----- From: "Zeev Suraski" <zeev@zend.com> To: "Adam Wright" <adam@elysium.ltd.uk> Cc: "PHP Development" <php-dev@lists.php.net> Sent: Friday, January 05, 2001 12:42 PM Subject: Re: Pretty mammoth security issue with safe_mode_exec At 14:11 5/1/2001, Adam Wright wrote:
If you have safe mode enabled, and have a safe mode exec directory,
here's
how you can execute binarys outside of your safe mode exec directory! Normally... system("../../../../../bin/cp blah blip"); would fail (as .. is blocked in _Exec (standard/exec.c) However... system("\.\./\.\./\.\./\.\./\.\./bin/cp blah blip"); will work fine! This is because the .. check was performed before the php_escape_shell_cmd in exec.c!
That's very very odd, because as far as system() (or any function for that matter) is concerned, ".." and "\.\." is exactly the same thing. At the scanner level, all the way down in the Zend Engine, it converts the bogus "\.\." string (which has illegal escapes) to "..". Are you sure this is the symptom exactly? Zeev -- Zeev Suraski <zeev@zend.com> CTO & co-founder, Zend Technologies Ltd. http://www.zend.com/
-- Zeev Suraski <zeev@zend.com> CTO & co-founder, Zend Technologies Ltd. http://www.zend.com/

« previous php.dev (#43042) next »