Re: Re: Pretty mammoth security issue with safe_mode_exec
| From: | Adam Wright | Date: | Fri, 05 Jan 2001 14:06:18 +0000 |
| Subject: | Re: Re: Pretty mammoth security issue with safe_mode_exec | ||
| References: | 1 2 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-43043@lists.php.net to get a copy of this message | ||
Ah. It's been a hard one to work out if its real or not due to our webserver
configuration. I'll do a little more testing, and hopefully patch it
sometime soon if I can convince myself of its reality :)
adamw
----- Original Message -----
From: "Zeev Suraski" <zeev@zend.com>
To: "Adam Wright" <adam@elysium.ltd.uk>
Cc: <php-dev@lists.php.net>
Sent: Friday, January 05, 2001 1:56 PM
Subject: [PHP-DEV] Re: Pretty mammoth security issue with safe_mode_exec
> Oh, well, actually I was too quick to respond - ".\" is indeed an invalid
> escape, but PHP treats it as ".\\", and not just ".".
>
> I just checked, shells indeed accept \.\. as if it was "..", so the bug is
> legit. If anybody attempts to fix it - note that \.. and .\. are also
> possible.
>
> Zeev
>
> At 14:56 5/1/2001, Adam Wright wrote:
> >Not to be annoying (well, not entirely), but if \. is parsed out at the
> >lexical level, why does...
> >
> ><?
> >
> >if ("\." == ".")
> > print "Same";
> >else
> > print "Different";
> >
> >echo "Different"?
> >
> >adamw
> >
> >----- Original Message -----
> >From: "Zeev Suraski" <zeev@zend.com>
> >To: "Adam Wright" <adam@elysium.ltd.uk>
> >Cc: "PHP Development" <php-dev@lists.php.net>
> >Sent: Friday, January 05, 2001 12:42 PM
> >Subject: Re: Pretty mammoth security issue with safe_mode_exec
> >
> >
> > > At 14:11 5/1/2001, Adam Wright wrote:
> > > >If you have safe mode enabled, and have a safe mode exec directory,
> >here's
> > > >how you can execute binarys outside of your safe mode exec directory!
> > > >
> > > >Normally...
> > > >
> > > >system("../../../../../bin/cp blah blip");
> > > >
> > > >would fail (as .. is blocked in _Exec (standard/exec.c)
> > > >
> > > >However...
> > > >
> > > >system("\.\./\.\./\.\./\.\./\.\./bin/cp blah blip");
> > > >
> > > >will work fine! This is because the .. check was performed before the
> > > >php_escape_shell_cmd in exec.c!
> > >
> > > That's very very odd, because as far as system() (or any function for
that
> > > matter) is concerned, ".." and "\.\." is exactly the same thing.
> > > At
the
> > > scanner level, all the way down in the Zend Engine, it converts the
bogus
> > > "\.\." string (which has illegal escapes) to "..".
> > >
> > > Are you sure this is the symptom exactly?
> > >
> > > Zeev
> > >
> > >
> > > --
> > > Zeev Suraski <zeev@zend.com>
> > > CTO & co-founder, Zend Technologies Ltd. »Ÿ>ö³¶™Ý
> > > 9Ohttp://www.zend.com/
> > >
> > >
>
> --
> Zeev Suraski <zeev@zend.com>
> CTO & co-founder, Zend Technologies Ltd. /Û+¬Díyþµ3“‘ÖÕ
> http://www.zend.com/
>
>
> --
> PHP Development Mailing List <http://www.php.net/>
> To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net
> For additional commands, e-mail: php-dev-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>
>