Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


Tutorial [Concept] cURL_exec not sanitized when used as a user-input filter_list
Author
Message
[Concept] cURL_exec not sanitized when used as a user-input #1
This tutorial is just to understand the concept when cURL_exec() is based on /controlled by user input .

What is cURL ?
cURL is a shortcut of "Client for URLs" , URL is spelled in uppercase just to make it so obvious that cURL deals with URLs .

cURL devides into two :

1- libcurl - a Client side transfer library supporting (HTTPS Certificates ,DICT, FILE, FTP, FTPS, GOPHER, HTTP, HTTPS, IMAP, IMAPS, LDAP, LDAPS, POP3, POP3S, RTMP, RTSP, SCP, SFTP, SMTP, SMTPS, TELNET and TFTP. . . . etc)
2- cURL - Which is a command lining tool for getting and sending (Files ,POST Data fields . . . etc) using URL synatx .

What is cURL_exec() ?
cURL_exec is a PHP function that it's usage is to execute a setted up cURL session( cURL initialization[curl_init();] , Option setting[CURL_SETOPT();] . . .) in a php script.
It actually does it's job when it's called so there's no actuall big deal with cURL_exec() .

What makes it a bit dangerous to make cURL_exec based on user input without user input sanitizing?

Let's assume that there's a script that uses cURL_exec() based on a user input session without sanitizing By other meaning the URL that is going to be used by cURL when initializing
is based on some user input without sanitizing the input , This can lead to some various vulnerabilities in your PHP script (Which is something that you don't really want to get infected with).

What various attacks could a user use against a URL used in curl based on user input ?
Example :

PHP Code:
<form method="post" action=""> <font color="red">URL : </font> <input type="text" name="url"> <button style="background-color:red;" name="Enter" type="submit" value="HTML">Log in!</button></center> <?php $link = $_POST['url']; if (isset($link)){ $ch = curl_init($link); /// cURL initialization with a user input URL curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); // writes the response to a variable $result = curl_exec($ch); // Executes the cURL session echo $result; } ?>

This form of script can be exploited if the attacker/user Uses the file:// protocol to read arbitary files from the server ex : file:///FILE-TO-READ , Which leads to local file disclosures.
In an older versions of libcurl such as 5.11(!) , libcurl was compiled to support SCP , So that it can be tricked to get a file using semicolons , Which can lead to
a Remote command execution .
Code:
EX : "scp://username:password@something/a'``;dir >/tmp/test``;'"

#bye

Reply

RE: [Concept] cURL_exec not sanitized when used as a user-input #2
www.hackforums.net/showthread.php?tid=4060569

Just quit trying, you're bad and always will be. Take your LQ copy and pasted tuts elsewhere.
XMPP - wrath@xmpp.jp

Reply

RE: [Concept] cURL_exec not sanitized when used as a user-input #3
(05-14-2014, 12:00 AM)Crypt Wrote: www.hackforums.net/showthread.php?tid=4060569

Just quit trying, you're bad and always will be. Take your LQ copy and pasted tuts elsewhere.

Give OP benefit of the doubt. Maybe he is.
#MakeSinisterlySexyAgain

Reply

RE: [Concept] cURL_exec not sanitized when used as a user-input #4
(05-14-2014, 12:00 AM)Crypt Wrote: www.hackforums.net/showthread.php?tid=4060569

Just quit trying, you're bad and always will be. Take your LQ copy and pasted tuts elsewhere.

Lmfao BeggFoMercy , Is another name of my nicknames , You just adjusted a huge failure .

Reply

RE: [Concept] cURL_exec not sanitized when used as a user-input #5
(05-14-2014, 12:13 AM)Z0le Wrote: Lmfao BeggFoMercy , Is another name of my nicknames , You just adjusted a huge failure .

Quit capitalizing all of the letters after a comma you illiterate little boy. This time, I didn't say it wasn't you. I told you to take your LQ copy and pasted tuts elsewhere. You obviously did copy and paste this, unless you actually took the time to re-write it.
XMPP - wrath@xmpp.jp

Reply

RE: [Concept] cURL_exec not sanitized when used as a user-input #6
Wait , re-writing a tutorial means that the writer knows every thing that is in the tutorial , That's a very good piece of evidence on your stupidity , Copy & pasted this ? Why not just send a URL of the source that I copy pasted my tutorial from .

Reply