Re: Re: Pretty mammoth security issue with safe_mode_exec

From: Date: Fri, 05 Jan 2001 14:06:18 +0000
Subject: Re: Re: Pretty mammoth security issue with safe_mode_exec
References: 1 2  Groups: php.dev 
Request: Send a blank email to php-dev+get-43043@lists.php.net to get a copy of this message
Ah. It's been a hard one to work out if its real or not due to our webserver configuration. I'll do a little more testing, and hopefully patch it sometime soon if I can convince myself of its reality :) adamw ----- Original Message ----- From: "Zeev Suraski" <zeev@zend.com> To: "Adam Wright" <adam@elysium.ltd.uk> Cc: <php-dev@lists.php.net> Sent: Friday, January 05, 2001 1:56 PM Subject: [PHP-DEV] Re: Pretty mammoth security issue with safe_mode_exec > Oh, well, actually I was too quick to respond - ".\" is indeed an invalid > escape, but PHP treats it as ".\\", and not just ".". > > I just checked, shells indeed accept \.\. as if it was "..", so the bug is > legit. If anybody attempts to fix it - note that \.. and .\. are also > possible. > > Zeev > > At 14:56 5/1/2001, Adam Wright wrote: > >Not to be annoying (well, not entirely), but if \. is parsed out at the > >lexical level, why does... > > > ><? > > > >if ("\." == ".") > > print "Same"; > >else > > print "Different"; > > > >echo "Different"? > > > >adamw > > > >----- Original Message ----- > >From: "Zeev Suraski" <zeev@zend.com> > >To: "Adam Wright" <adam@elysium.ltd.uk> > >Cc: "PHP Development" <php-dev@lists.php.net> > >Sent: Friday, January 05, 2001 12:42 PM > >Subject: Re: Pretty mammoth security issue with safe_mode_exec > > > > > > > At 14:11 5/1/2001, Adam Wright wrote: > > > >If you have safe mode enabled, and have a safe mode exec directory, > >here's > > > >how you can execute binarys outside of your safe mode exec directory! > > > > > > > >Normally... > > > > > > > >system("../../../../../bin/cp blah blip"); > > > > > > > >would fail (as .. is blocked in _Exec (standard/exec.c) > > > > > > > >However... > > > > > > > >system("\.\./\.\./\.\./\.\./\.\./bin/cp blah blip"); > > > > > > > >will work fine! This is because the .. check was performed before the > > > >php_escape_shell_cmd in exec.c! > > > > > > That's very very odd, because as far as system() (or any function for that > > > matter) is concerned, ".." and "\.\." is exactly the same thing. > > > At the > > > scanner level, all the way down in the Zend Engine, it converts the bogus > > > "\.\." string (which has illegal escapes) to "..". > > > > > > Are you sure this is the symptom exactly? > > > > > > Zeev > > > > > > > > > -- > > > Zeev Suraski <zeev@zend.com> > > > CTO & co-founder, Zend Technologies Ltd. »Ÿ>ö³¶™Ý > > > 9Ohttp://www.zend.com/ > > > > > > > > -- > Zeev Suraski <zeev@zend.com> > CTO & co-founder, Zend Technologies Ltd. /Û+¬Díyþµ3“‘ÖÕ > http://www.zend.com/ > > > -- > PHP Development Mailing List <http://www.php.net/> > To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net > For additional commands, e-mail: php-dev-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net > >

« previous php.dev (#43043) next »