Vulnerability Development mailing list archives
RE: PHP Disclosure issue
From: PJD () portcullis-security com
Date: Thu, 17 May 2001 09:40:16 +0100
I guess my point has been missed. Many applications/systems have options such as debug mode, verbose or php_info(), all of which are invaluable during development/debugging. Whilst I am not saying these are vulnerabilities, I am saying that these should not be left on in production environments as they often disclose unnecessary or important information. The difference being that whilst this is not a directly exploitable vulnerability, it discloses information specific to the system that allows a more focused approach which could lead to the system being exploited. Further to all of this I do not believe that the developers are responsible as they have clearly stated in their response that it is documented, hence my point about the administrator rather than the developer. Finally, the use of errors to produce vulnerabilities is well known and well documented, even as far back as Bletchley Park and the Enigma, some of Turin's theorys and in fact the basis for Colossus was on the processing of errors. Cheers
---------- From: Kevin J. Menard, Jr.[SMTP:kmenard () WPI EDU] Reply To: Kevin J. Menard, Jr. Sent: Tuesday, May 15, 2001 2:36 PM To: vuln-dev () securityfocus com Subject: Re: PHP Disclosure issue Would you then consider the php_info() function to be a security flaw? I don't consider this to be a vulnerability discovered. Anyone who's developed with language knows what kind of information is spit out on errors. ----- Original Message ----- From: <PJD () portcullis-security com> To: <PEN-TEST () securityfocus com>; <VULN-DEV () securityfocus com> Sent: Saturday, May 12, 2001 11:24 PM Subject: PHP Disclosure issueHi guys Recently we discovered a path disclosure vulnerability in PHP3. This issue has been discussed with the vendor, and further to thisIhave included some of the comments made by them within this mail. [Excerpt from mail to vendor] On NT 4 Server with SP5 installed, running IIS4 with PHP 3 itpossibleto request a nonexistent file and the response is an error which returns the wwwroot e.g. requesting the following in the browser-Exploit example: http://www.somewhere.com/notthere.php3 returns the following errorinthe browser window - Unable to open c:\<wwwroot\notthere.php3 in - on line 0 No Inputfilespecified Having discussed this with the vendor, they have responded sayingthatthis is a configuration error, and is simply rectified by changingasetting from the default within the configuration .ini file. [Snippit from the response] "I don't consider this as a security flaw; The distributed php.ini-dist includes the following information (for a few months,ifnot years): display_errors = On ; Print out errors (as a part of theoutput) ;For production web sites, you're strongly encouraged; to turn this feature off, and use error logginginstead(see below).; Keeping display_errors enabled on a production websitemay reveal; security information to end users, such as file pathsonyour Web server, your database schema or other information The fact that the full error information that helps you fix the problem is not a flaw, and is not going to change. PHP comes outofthe box for development-oriented audience; You have to configureitslightly differently when you turn into production." [End] We see this as akin to the .idq type issue in IIS. Additionally,asall errors are returned to the browser it could be possible to use PHP3 to generate further errors that could output information onotherweb resourses within that environment. This discovery was made by John Clayton, from here at Portcullis. Regards Paul Docherty-- Kevin
Current thread:
- Re: PHP Disclosure issue Kevin J. Menard, Jr. (May 15)
- <Possible follow-ups>
- RE: PHP Disclosure issue PJD (May 15)
- Re: PHP Disclosure issue Eric Fitzgerald (May 15)
- RE: PHP Disclosure issue PJD (May 17)
