daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

disable-functions-bypass-php-5-2-fopen-exploit.md (1514B)


      1 ---
      2 title: "PHP 5.2 fopen safemode Bypass"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-5.2-fopen-exploit.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-5.2-fopen-exploit.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # PHP 5.2 `fopen` `safe_mode` Bypass
     14 
     15 This historical local exploit targets a `safe_mode` restriction-bypass issue reported in PHP 5.2.0. In a shared-hosting scenario where an attacker could already execute PHP code, a crafted `srpath://` URI passed to `fopen` could write a file outside the intended location.<sup>[[1]](#references)</sup> This is not a general bypass for modern PHP because `safe_mode` and its related configuration options were removed in PHP 5.4.<sup>[[2]](#references)</sup>
     16 
     17 ```bash
     18 php -r 'fopen("srpath://../../../../../../../dir/pliczek", "a");'
     19 ```
     20 
     21 ## References
     22 
     23 - [1] [Exploit Database - PHP 5.2 `fopen` `safe_mode` Restriction Bypass](https://gitlab.com/exploit-database/exploitdb/-/blob/main/exploits/php/local/29528.txt)
     24 - [2] [PHP 5.4.0 Release Announcement](https://www.php.net/releases/5_4_0.php)