[Concept] cURL_exec not sanitized when used as a user-input 05-13-2014, 11:37 PM
#1
This tutorial is just to understand the concept when cURL_exec() is based on /controlled by user input .
What is cURL ?
cURL is a shortcut of "Client for URLs" , URL is spelled in uppercase just to make it so obvious that cURL deals with URLs .
cURL devides into two :
1- libcurl - a Client side transfer library supporting (HTTPS Certificates ,DICT, FILE, FTP, FTPS, GOPHER, HTTP, HTTPS, IMAP, IMAPS, LDAP, LDAPS, POP3, POP3S, RTMP, RTSP, SCP, SFTP, SMTP, SMTPS, TELNET and TFTP. . . . etc)
2- cURL - Which is a command lining tool for getting and sending (Files ,POST Data fields . . . etc) using URL synatx .
What is cURL_exec() ?
cURL_exec is a PHP function that it's usage is to execute a setted up cURL session( cURL initialization[curl_init();] , Option setting[CURL_SETOPT();] . . .) in a php script.
It actually does it's job when it's called so there's no actuall big deal with cURL_exec() .
What makes it a bit dangerous to make cURL_exec based on user input without user input sanitizing?
Let's assume that there's a script that uses cURL_exec() based on a user input session without sanitizing By other meaning the URL that is going to be used by cURL when initializing
is based on some user input without sanitizing the input , This can lead to some various vulnerabilities in your PHP script (Which is something that you don't really want to get infected with).
What various attacks could a user use against a URL used in curl based on user input ?
Example :
This form of script can be exploited if the attacker/user Uses the file:// protocol to read arbitary files from the server ex : file:///FILE-TO-READ , Which leads to local file disclosures.
In an older versions of libcurl such as 5.11(!) , libcurl was compiled to support SCP , So that it can be tricked to get a file using semicolons , Which can lead to
a Remote command execution .
#bye
What is cURL ?
cURL is a shortcut of "Client for URLs" , URL is spelled in uppercase just to make it so obvious that cURL deals with URLs .
cURL devides into two :
1- libcurl - a Client side transfer library supporting (HTTPS Certificates ,DICT, FILE, FTP, FTPS, GOPHER, HTTP, HTTPS, IMAP, IMAPS, LDAP, LDAPS, POP3, POP3S, RTMP, RTSP, SCP, SFTP, SMTP, SMTPS, TELNET and TFTP. . . . etc)
2- cURL - Which is a command lining tool for getting and sending (Files ,POST Data fields . . . etc) using URL synatx .
What is cURL_exec() ?
cURL_exec is a PHP function that it's usage is to execute a setted up cURL session( cURL initialization[curl_init();] , Option setting[CURL_SETOPT();] . . .) in a php script.
It actually does it's job when it's called so there's no actuall big deal with cURL_exec() .
What makes it a bit dangerous to make cURL_exec based on user input without user input sanitizing?
Let's assume that there's a script that uses cURL_exec() based on a user input session without sanitizing By other meaning the URL that is going to be used by cURL when initializing
is based on some user input without sanitizing the input , This can lead to some various vulnerabilities in your PHP script (Which is something that you don't really want to get infected with).
What various attacks could a user use against a URL used in curl based on user input ?
Example :
PHP Code:
<form method="post" action="">
<font color="red">URL : </font> <input type="text" name="url">
<button style="background-color:red;" name="Enter" type="submit" value="HTML">Log in!</button></center>
<?php
$link = $_POST['url'];
if (isset($link)){
$ch = curl_init($link); /// cURL initialization with a user input URL
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); // writes the response to a variable
$result = curl_exec($ch); // Executes the cURL session
echo $result;
}
?>This form of script can be exploited if the attacker/user Uses the file:// protocol to read arbitary files from the server ex : file:///FILE-TO-READ , Which leads to local file disclosures.
In an older versions of libcurl such as 5.11(!) , libcurl was compiled to support SCP , So that it can be tricked to get a file using semicolons , Which can lead to
a Remote command execution .
Code:
EX : "scp://username:password@something/a'``;dir >/tmp/test``;'"#bye

![[+]](https://sinister.li/images/modern/collapse_collapsed.png)
















