PHP-CGI Vulnerability Exploited in the Wild
blog.sucuri.net
blog.sucuri.net
However, I then also tried to run remote code execution and couldn't. The only differences to my stack is that it's running Nginx and hops accross a few proxies (nginx -> varnish -> nginx (for SSL and SSI)) in between. I'm not sure why I can't run -d or -n, but any other options seems to always return the source.
Anyone else running nginx in fastcgi noticing similar? It seems like it's vulernable to the source download, however not remote execution. I'm about to work on a rewrite rule now just in case.
(Not sure why it's vulnerable to the source download, as comment below says, it's set up to not be vulnerable?)
Edit: Not sure what part of my comment deserved the down vote. I trust that what you say is true, in that fastcgi is explicitly set up to negate this vulnerability, but the truth remains that I am experiencing it. If anything I'd have wanted to reach out to other nginx users...
The only way I could ever show that fastcgi under nginx is vulnerable, would be by linking to my live vulnerable server running nginx.. and the wiseman inside of me knows that to be a bad idea! Ha.
Edit: Are you proxying to an Apache server that runs PHP-CGI?
They really do have a sense of humour...
Server: '; DROP TABLE servertypes; --http://www.shodanhq.com/search?q=DROP+TABLE+servertypes
And other companies offer job offers in their headers as well:
https://help.us.army.mil/cgi-bin/akohd.cfg/php/enduser/std_a...
https://help.auctions.overstock.com/app/answers/detail/a_id/...
http://askus.columbia.edu/app/answers/list/p/0/kw/student%20...
http://help.station.sony.com/app/answers/detail/a_id/10404?-...
http://nam-en.apc.com/cgi-bin/nam_en.cfg/php/enduser/std_adp...
http://help.linkedin.com/cgi-bin/linkedin.cfg/php/enduser/st...
http://askdrs.ct.gov/Scripts/drsrightnow.cfg/php.exe/enduser...
http://askfsis.custhelp.com/app/answers/detail/a_id/1249?-s
http://linksys.custhelp.com/cgi-bin/linksys.cfg/php/enduser/...
http://ubisoft.custhelp.com/cgi-bin/ubisoft.cfg/php/enduser/...
https://ebay.custhelp.com/cgi-bin/ebay.cfg/php/enduser/std_a...
Also, one would assume that any website still using php-cgi has plenty of other security vulnerabilities.
I would be surprised if these systems haven't already been p0wned a long time ago.
I bet there are still tens of thousands of otherwise secure php-cgi setups out there.
If you use mod_php, every customer's code runs as the apache user, which is bad for security. If you use PHP-FPM, you end up needing at least one long-running process per user, which wastes resources.
I myself run LigHTTPD and PHP through FastCGI, and this was worrying me a lot, until someone pointed me to the Eindbazen site which stated this.
(BTW: Eindbazen is Dutch for "Final boss" in a video game context.)