Date: 01/05/01
- Next message: Adam Wright: "[PHP-DEV] Re: Pretty mammoth security issue with safe_mode_exec"
- Previous message: Zeev Suraski: "Re: [PHP-DEV] Re: 4.0.4pl1 RC1 rolled"
- In reply to: Zeev Suraski: "[PHP-DEV] Re: Pretty mammoth security issue with safe_mode_exec"
- Next in thread: Adam Wright: "[PHP-DEV] Re: Pretty mammoth security issue with safe_mode_exec"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
99.9999% sure. Try it and see.
adamw
----- Original Message -----
From: "Zeev Suraski" <zeev <email protected>>
To: "Adam Wright" <adam <email protected>>
Cc: "PHP Development" <php-dev <email protected>>
Sent: Friday, January 05, 2001 12:42 PM
Subject: [PHP-DEV] Re: Pretty mammoth security issue with safe_mode_exec
> At 14:11 5/1/2001, Adam Wright wrote:
> >If you have safe mode enabled, and have a safe mode exec directory,
here's
> >how you can execute binarys outside of your safe mode exec directory!
> >
> >Normally...
> >
> >system("../../../../../bin/cp blah blip");
> >
> >would fail (as .. is blocked in _Exec (standard/exec.c)
> >
> >However...
> >
> >system("\.\./\.\./\.\./\.\./\.\./bin/cp blah blip");
> >
> >will work fine! This is because the .. check was performed before the
> >php_escape_shell_cmd in exec.c!
>
> That's very very odd, because as far as system() (or any function for that
> matter) is concerned, ".." and "\.\." is exactly the same thing. At the
> scanner level, all the way down in the Zend Engine, it converts the bogus
> "\.\." string (which has illegal escapes) to "..".
>
> Are you sure this is the symptom exactly?
>
> Zeev
>
>
> --
> Zeev Suraski <zeev <email protected>>
> CTO & co-founder, Zend Technologies Ltd. http://www.zend.com/
>
>
> --
> PHP Development Mailing List <http://www.php.net/>
> To unsubscribe, e-mail: php-dev-unsubscribe <email protected>
> For additional commands, e-mail: php-dev-help <email protected>
> To contact the list administrators, e-mail: php-list-admin <email protected>
>
>
-- PHP Development Mailing List <http://www.php.net/> To unsubscribe, e-mail: php-dev-unsubscribe <email protected> For additional commands, e-mail: php-dev-help <email protected> To contact the list administrators, e-mail: php-list-admin <email protected>
- Next message: Adam Wright: "[PHP-DEV] Re: Pretty mammoth security issue with safe_mode_exec"
- Previous message: Zeev Suraski: "Re: [PHP-DEV] Re: 4.0.4pl1 RC1 rolled"
- In reply to: Zeev Suraski: "[PHP-DEV] Re: Pretty mammoth security issue with safe_mode_exec"
- Next in thread: Adam Wright: "[PHP-DEV] Re: Pretty mammoth security issue with safe_mode_exec"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

