Home Backend Development PHP Tutorial PHP-5.3.9 Remote Arbitrary Code Execution Vulnerability (CVE-2012-0830) Detailed Explanation_PHP Tutorial

PHP-5.3.9 Remote Arbitrary Code Execution Vulnerability (CVE-2012-0830) Detailed Explanation_PHP Tutorial

Jul 13, 2016 pm 05:10 PM
h php code I implement loopholes Detailed explanation Remotely

Remember the PHP Hash Collisions Ddos vulnerability I mentioned before? At first, the repair plan given by the development team was to report an error (E_ERROR) if it exceeds max_input_vars, which in turn caused PHP to end with an error. Later, In order to solve this problem more lightweight, we improved it and changed it to issue a warning (E_WARNING) if max_input_vars is exceeded, and no longer add to the destination array, but the process continues. Then we released 5.3.9.

This new fix has good intentions, but it brings about a serious problem (fixed in 5.3.10), which was originally discovered by Stefan Esser. Please see the previous (5.3.9) final Fix (php_register_variable_ex):

The code is as follows Copy code
 代码如下 复制代码

while (1) {

     if (zend_symtable_find(symtable1, escaped_index, index_len + 1, (void **) &gpc_element_p) == FAILURE

          || Z_TYPE_PP(gpc_element_p) != IS_ARRAY) { //(3)

          if (zend_hash_num_elements(symtable1) <= PG(max_input_vars)) { // (4)

if (zend_hash_num_elements(symtable1) == PG(max_input_vars)) {

php_error_docref(NULL TSRMLS_CC, E_WARNING, "Input variables exceeded %ld. ...", PG(max_input_vars)); // (1)

}

MAKE_STD_ZVAL(gpc_element);

array_init(gpc_element);

zend_symtable_update(symtable1, escaped_index, index_len + 1, &gpc_element, sizeof(zval *), (void **) &gpc_element_p);

}

//......

}

//.....

symtable1 = Z_ARRVAL_PP(gpc_element_p); // (2)

goto plain;

}< li>

while (1) { if (zend_symtable_find(symtable1, escaped_index, index_len + 1, (void **) &gpc_element_p) == FAILURE || Z_TYPE_PP(gpc_element_p) != IS_ARRAY) { //(3) If (zend_hash_num_elements(symtable1) <= PG(max_input_vars)) { // (4)<🎜> <🎜> if (zend_hash_num_elements(symtable1) == PG(max_input_vars)) {<🎜> <🎜> php_error_docref(NULL TSRMLS_CC, E_WARNING, "Input variables exceeded %ld. ...", PG(max_input_vars)); // (1)<🎜> <🎜>          }<🎜> <🎜> MAKE_STD_ZVAL(gpc_element);<🎜> <🎜> array_init(gpc_element);<🎜> <🎜> zend_symtable_update(symtable1, escaped_index, index_len + 1, &gpc_element, sizeof(zval *), (void **) &gpc_element_p);<🎜> <🎜> }<🎜> <🎜>           //......<🎜> <🎜> }<🎜> <🎜> //.....<🎜> <🎜> symtable1 = Z_ARRVAL_PP(gpc_element_p); // (2)<🎜> <🎜> goto plain;<🎜> <🎜>}< li>


Note that if you register an array variable at this time (similar to: a[]=2 in GET), and this variable happens to be the max_input_vars-th variable, a warning (1) will be triggered, and everything is normal at this time. .

However, if you still register an array variable at this time, but this variable is already the max_input_vars + 1th variable, then gpc_element_p will become an uninitialized pointer at this time, and because the logic will continue now, that is will go to position (2), causing an uninitialized pointer to be dereferenced. So, Boomb~

So, at this point, we can use this feature to do Ddos on 5.3.9. If the Server has Core Dump enabled, the effect will be very obvious.

However, this problem can also lead to a more serious problem:

Still the above code, there is a loop in the outermost layer. When this loop takes effect, when registering a pair similar to a[b]=2, the loop will be executed twice. The first time a will be inserted. [], insert b into a[] for the second time. Then let us pay attention to (3). If the desired element cannot be found in the destination array, **or the element is not an array**, then It will also directly cause the process to be left to (2), so problems arise.

For a POST string like this (default max_input_vars is 1000):

1=1&1=2&..........&999=1&x="I am a malicious string"&x[0]=


What will happen?

Let me describe it step by step:

1. There is no problem from 1 to 999, they are all inserted normally

2. x is 1000 elements, so a warning is triggered and there is no problem, x is inserted

3. When x[0] is inserted, statement (3) determines that it is not Arrary and enters the if body. However, statement (4) fails at this time, so the process finally flows to (2)

4. At this time, gpc_element_p points to x, which is the string we forged...

Now let’s look at the key data structure, zval:

The code is as follows Copy code
 代码如下 复制代码

struct _zval_struct {

    /* Variable information */

    zvalue_value value; /* value */

    zend_uint refcount__gc;

    zend_uchar type; /* active type */

    zend_uchar is_ref__gc;

};< li>

struct _zval_struct {


/* Variable information */

 代码如下 复制代码

typedef union _zvalue_value {

    long lval; /* long value */

    double dval; /* double value */

    struct {

        char *val;

        int len;

    } str;

    HashTable *ht; /* hash table value */

    zend_object_value obj;

} zvalue_value;< li>

zvalue_value value; /* value */ zend_uint refcount__gc; zend_uchar type; /* active type */ zend_uchar is_ref__gc; };< li>
Then look at zvalue_value:
The code is as follows Copy code
typedef union _zvalue_value { long lval; /* long value */ double dval; /* double value */ struct { char *val; int len; } str; HashTable *ht; /* hash table value */ zend_object_value obj; } zvalue_value;< li>


zvalue_value is a union, so the memory of the string area we construct will be treated as a Hashtable structure:

uint nTableMask;
The code is as follows
 代码如下 复制代码

typedef struct _hashtable {

    uint nTableSize;

    uint nTableMask;

    uint nNumOfElements;

    ulong nNextFreeElement;

    Bucket *pInternalPointer; /* Used for element traversal */

    Bucket *pListHead;

    Bucket *pListTail;

    Bucket **arBuckets;

    dtor_func_t pDestructor; //注意这个

    zend_bool persistent;

    unsigned char nApplyCount;

    zend_bool bApplyProtection;

#if ZEND_DEBUG

    int inconsistent;

#endif

} HashTable;< li>

Copy code


typedef struct _hashtable {

uint nTableSize;
uint nNumOfElements;

ulong nNextFreeElement; Bucket *pInternalPointer; /* Used for element traversal */ Bucket *pListHead; Bucket *pListTail; Bucket **arBuckets; dtor_func_t pDestructor; //Pay attention to this zend_bool persistent;
unsigned char nApplyCount;
zend_bool bApplyProtection;
#if ZEND_DEBUG int inconsistent; #endif } HashTable;
  • In the Hashtable structure, there is a pDestructor. This pointer points to a function. When there are elements in the Hashtable that need to be cleared, it will be called... In other words, you can set an address (pDestructor) as you like, and then let PHP call it (inducing an element to be deleted). http://www.bkjia.com/PHPjc/629666.htmlwww.bkjia.comtruehttp: //www.bkjia.com/PHPjc/629666.htmlTechArticleDo you still remember the PHP Hash Collisions Ddos vulnerability I mentioned before? At the beginning, the repair plan provided by the development team , what is used is that if max_input_vars is exceeded, an error (E_ERROR) will be reported, which will lead to P...
  • Statement of this Website
    The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn

    Hot AI Tools

    Undresser.AI Undress

    Undresser.AI Undress

    AI-powered app for creating realistic nude photos

    AI Clothes Remover

    AI Clothes Remover

    Online AI tool for removing clothes from photos.

    Undress AI Tool

    Undress AI Tool

    Undress images for free

    Clothoff.io

    Clothoff.io

    AI clothes remover

    Video Face Swap

    Video Face Swap

    Swap faces in any video effortlessly with our completely free AI face swap tool!

    Hot Article

    Roblox: Bubble Gum Simulator Infinity - How To Get And Use Royal Keys
    3 weeks ago By 尊渡假赌尊渡假赌尊渡假赌
    Nordhold: Fusion System, Explained
    4 weeks ago By 尊渡假赌尊渡假赌尊渡假赌
    Mandragora: Whispers Of The Witch Tree - How To Unlock The Grappling Hook
    3 weeks ago By 尊渡假赌尊渡假赌尊渡假赌

    Hot Tools

    Notepad++7.3.1

    Notepad++7.3.1

    Easy-to-use and free code editor

    SublimeText3 Chinese version

    SublimeText3 Chinese version

    Chinese version, very easy to use

    Zend Studio 13.0.1

    Zend Studio 13.0.1

    Powerful PHP integrated development environment

    Dreamweaver CS6

    Dreamweaver CS6

    Visual web development tools

    SublimeText3 Mac version

    SublimeText3 Mac version

    God-level code editing software (SublimeText3)

    Hot Topics

    Java Tutorial
    1670
    14
    PHP Tutorial
    1274
    29
    C# Tutorial
    1256
    24
    PHP: A Key Language for Web Development PHP: A Key Language for Web Development Apr 13, 2025 am 12:08 AM

    PHP is a scripting language widely used on the server side, especially suitable for web development. 1.PHP can embed HTML, process HTTP requests and responses, and supports a variety of databases. 2.PHP is used to generate dynamic web content, process form data, access databases, etc., with strong community support and open source resources. 3. PHP is an interpreted language, and the execution process includes lexical analysis, grammatical analysis, compilation and execution. 4.PHP can be combined with MySQL for advanced applications such as user registration systems. 5. When debugging PHP, you can use functions such as error_reporting() and var_dump(). 6. Optimize PHP code to use caching mechanisms, optimize database queries and use built-in functions. 7

    PHP vs. Python: Understanding the Differences PHP vs. Python: Understanding the Differences Apr 11, 2025 am 12:15 AM

    PHP and Python each have their own advantages, and the choice should be based on project requirements. 1.PHP is suitable for web development, with simple syntax and high execution efficiency. 2. Python is suitable for data science and machine learning, with concise syntax and rich libraries.

    PHP and Python: Comparing Two Popular Programming Languages PHP and Python: Comparing Two Popular Programming Languages Apr 14, 2025 am 12:13 AM

    PHP and Python each have their own advantages, and choose according to project requirements. 1.PHP is suitable for web development, especially for rapid development and maintenance of websites. 2. Python is suitable for data science, machine learning and artificial intelligence, with concise syntax and suitable for beginners.

    PHP in Action: Real-World Examples and Applications PHP in Action: Real-World Examples and Applications Apr 14, 2025 am 12:19 AM

    PHP is widely used in e-commerce, content management systems and API development. 1) E-commerce: used for shopping cart function and payment processing. 2) Content management system: used for dynamic content generation and user management. 3) API development: used for RESTful API development and API security. Through performance optimization and best practices, the efficiency and maintainability of PHP applications are improved.

    The Enduring Relevance of PHP: Is It Still Alive? The Enduring Relevance of PHP: Is It Still Alive? Apr 14, 2025 am 12:12 AM

    PHP is still dynamic and still occupies an important position in the field of modern programming. 1) PHP's simplicity and powerful community support make it widely used in web development; 2) Its flexibility and stability make it outstanding in handling web forms, database operations and file processing; 3) PHP is constantly evolving and optimizing, suitable for beginners and experienced developers.

    PHP and Python: Different Paradigms Explained PHP and Python: Different Paradigms Explained Apr 18, 2025 am 12:26 AM

    PHP is mainly procedural programming, but also supports object-oriented programming (OOP); Python supports a variety of paradigms, including OOP, functional and procedural programming. PHP is suitable for web development, and Python is suitable for a variety of applications such as data analysis and machine learning.

    PHP vs. Other Languages: A Comparison PHP vs. Other Languages: A Comparison Apr 13, 2025 am 12:19 AM

    PHP is suitable for web development, especially in rapid development and processing dynamic content, but is not good at data science and enterprise-level applications. Compared with Python, PHP has more advantages in web development, but is not as good as Python in the field of data science; compared with Java, PHP performs worse in enterprise-level applications, but is more flexible in web development; compared with JavaScript, PHP is more concise in back-end development, but is not as good as JavaScript in front-end development.

    PHP and Python: Code Examples and Comparison PHP and Python: Code Examples and Comparison Apr 15, 2025 am 12:07 AM

    PHP and Python have their own advantages and disadvantages, and the choice depends on project needs and personal preferences. 1.PHP is suitable for rapid development and maintenance of large-scale web applications. 2. Python dominates the field of data science and machine learning.

    See all articles