php / php/php-src

Set register_argc_argv to Off by default

Aperta
#12,344 9 commenti 3 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Feature Status: Needs Triage
Lingua principale
C
Stelle
40.4k
Fork
8.1k
Merge medio
2g 13h
PR unite (30g)
96

Descrizione

(I'm not reporting this as a security issue as it's about a setting "[...] not recommended for production - ex. error reporting to output" or "[...] known to be insecure".)

Many PHP CLI tools are shipped in the form of Phar files (e.g. Composer), and while never really recommended, some users tend to put these archives under the web root (tutorials from shared hosting providers, when you need per-project Composer releases, etc.). On distributions like Debian and Ubuntu, Apache is treating these files as PHP scripts.

Since these scripts use $_SERVER['argc'] to find out how they are invoked and parse their arguments, direct access to these files is not a problem when register_argc_argv is set to Off. Looking into this topic, I noticed that PHP is still shipped with register_argc_argv set to On by default:

https://github.com/php/php-src/blob/21d9fd3bc1ccf376438e4b5c38bb1945ae3bfe8c/main/main.c#L709

The recommended default configuration for the production environment and shipped with most distributions set it to Off–note that it only mentions performance reasons and not security:

https://github.com/php/php-src/blob/21d9fd3bc1ccf376438e4b5c38bb1945ae3bfe8c/php.ini-production#L677-L690

There are still environments in which this setting can be set to On, either involuntarily by keeping the development configuration or voluntarily by manually setting it. For instance, the main PHP Docker image for PHP has it set to On.

We can then assume that there is a non-zero chance of deployments processing Phar files as PHP scripts and with this setting left to its default value, introducing potential vulnerabilities. I've already reached out to Composer and they now refuse to run in non-CLI SAPIs if register_argc_argv is On (CVE-2023-43655).

Outside of the risk caused by Phar files, register_argc_argv is also a known "trick" to exploit limited Local File Inclusion vulnerabilities in a generic way in Docker php images, using /usr/local/lib/php/pearcmd.php (i.e. 2linephp by @w181496 during Balsn CTF 2021). This exploitation method was also shared with a wider audience in a video of @JohnHammond (https://www.youtube.com/watch?v=yq2rq50IMSQ).

I think it would be great to set register_argc_argv to Off by default, keeping it to On only for these SAPIs: embed, phpdbg and cli. I'm not sure about litespeed but from what I'm reading in the code, it seems important too. The documentation in php.ini could also mention the potential security risks caused by this setting.

I'll be happy to work on the PR if this sounds like something that could happen to be merged, let me know!

Guida per i contributori

Apri la guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Direzione di ricerca

Iniziare esaminando il valore predefinito di register_argc_argv in main/main.c e le indicazioni corrispondenti in php.ini-production. Tracciare il modo in cui l'impostazione si applica alle SAPI embed, phpdbg, cli e litespeed, quindi determinare l'impatto sulla compatibilità della modifica del valore predefinito. Il lavoro è completato quando il comportamento predefinito e la documentazione di php.ini riflettono coerentemente la policy SAPI accettata.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
c, php
Ambito
backend, security
Tipo di issue
Funzionalità
Difficoltà
5/5
Tempo stimato
Più di una settimana
Stato di attività
Ferma
Chiarezza
Abbastanza chiara
Idoneità per principianti
32/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.