disable-functions-bypass-php-5-2-fopen-exploit.md (1514B)
1 --- 2 title: "PHP 5.2 fopen safemode Bypass" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-5.2-fopen-exploit.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-5.2-fopen-exploit.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # PHP 5.2 `fopen` `safe_mode` Bypass 14 15 This historical local exploit targets a `safe_mode` restriction-bypass issue reported in PHP 5.2.0. In a shared-hosting scenario where an attacker could already execute PHP code, a crafted `srpath://` URI passed to `fopen` could write a file outside the intended location.<sup>[[1]](#references)</sup> This is not a general bypass for modern PHP because `safe_mode` and its related configuration options were removed in PHP 5.4.<sup>[[2]](#references)</sup> 16 17 ```bash 18 php -r 'fopen("srpath://../../../../../../../dir/pliczek", "a");' 19 ``` 20 21 ## References 22 23 - [1] [Exploit Database - PHP 5.2 `fopen` `safe_mode` Restriction Bypass](https://gitlab.com/exploit-database/exploitdb/-/blob/main/exploits/php/local/29528.txt) 24 - [2] [PHP 5.4.0 Release Announcement](https://www.php.net/releases/5_4_0.php)