#45229 [Opn->Csd]: "Insecure" Installation Configuration

From: Date: Tue, 24 Jun 2008 21:54:43 +0000
Subject: #45229 [Opn->Csd]: "Insecure" Installation Configuration
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-909@lists.php.net to get a copy of this message
ID: 45229 Updated by: danbrown@php.net Reported By: phpbugs at rjharrison dot org -Status: Open +Status: Closed Bug Type: Documentation problem Operating System: *nix PHP Version: Irrelevant New Comment: This bug has been fixed in the documentation's XML sources. Since the online and downloadable versions of the documentation need some time to get updated, we would like to ask you to be a bit patient. Thank you for the report, and for helping us make our documentation better. I've been using that same method for quite some time on all of my servers as well. Thanks for bringing it to our attention to add it into the documentation for others to benefit, too. Previous Comments: ------------------------------------------------------------------------ [2008-06-10 16:52:00] phpbugs at rjharrison dot org Description: ------------ The install instructions for *nix + Apache suggest a *potentially* *less secure* configuration of Apache. http://www.php.net/manual/en/install.unix.apache2.php "AddType application/x-httpd-php .php .phtml" The potential vulnerability involves how Apache handles files with multiple extensions. A file named exploit.php.xx.xx will be interpreted as PHP; so if a file was uploaded, a simple check on its extension against a blacklist (.php, .cgi etc) would allow a .php.xx.xx file to pass. Put aside the issue of developer stupidity: instead of the AddType... configuration, we could change it to:- <FilesMatch \.php$> SetHandler application/x-httpd-php </FilesMatch> Which I don't think has any side-effects and means only files with extension .php would be interpreted. Reproduce code: --------------- [Vanilla Apache+PHP installation from source] Filename: exploit.php.xx.xx <?php echo "Oh shit, this ran through PHP!"; ?> When you request http://localhost/exploit.php.xx.xx it will be interpreted by PHP. ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=45229&edit=1

« previous php.doc.bugs (#909) next »