#19160 [NEW]: fopen doesn't remove space, CR, LF from URL's
| From: | ulfh at update dot uu dot se | Date: | Wed, 28 Aug 2002 22:35:42 +0000 |
| Subject: | #19160 [NEW]: fopen doesn't remove space, CR, LF from URL's | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-18092@lists.php.net to get a copy of this message | ||
From: ulfh@update.uu.se
Operating system: Linux (Red Hat, Debian)
PHP version: 4.2.2
PHP Bug Type: HTTP related
Bug description: fopen doesn't remove space, CR, LF from URL's
As you know, you can use URL's in fopen(), file() etc when allow_url_fopen
is On. Unfortunately, PHP doesn't remove spaces, tabs, CR or LF characters
from the URL before constructing an HTTP query. This means that we can add
arbitrary HTTP headers to the URL, like this:
<?php
$fp = fopen("http://www.site1.st/ HTTP/1.0\n".
"Host: www.site2.st\n".
"User-Agent: Nozilla/0.0\n".
"Referer: http://www.metaur.nu/\n".
"Cookie: user=ulf\n\n", "r");
fpassthru($fp);
?>
This program will display the contents of site2.st instead of site1.st, if
they live on the same virtual host.
You can also use it for communication with other types of servers than
HTTP servers:
<?php
$fp = fopen("http://mail.site1.st:25/ HTTP/1.0\n".
"HELO my.own.machine\n".
"MAIL FROM: <user@my.own.machine>\n".
"RCPT TO: <info@site1.st>\n".
"DATA\n".
"From: user@my.own.machine\n".
"To: info@site1.st\n".
"Subject: This is..\n\n".
"This is a URL that sends an e-mail (?).\n".
".\n".
"QUIT\n\n", "r");
fpassthru($fp);
?>
Both the mail server and PHP will complain, but the mail still gets sent.
This can even lead to a security hole in a program like this:
<?php
$fp = fopen("http://www.site3.st/$path",
"r");
fpassthru($fp);
?>
because it allows the user to break out of restrictions and access some
other site than site3.st.
I have verified this behaviour in PHP 4.1.2, 4.2.2 and a CVS checkout from
a few days ago. You fix it by removing all spaces, tabs, CR characters and
LF characters from the URL's.
// Ulf Harnhammar
ulfh@update.uu.se
--
Edit bug report at http://bugs.php.net/?id=19160&edit=1
--
Try a CVS snapshot: http://bugs.php.net/fix.php?id=19160&r=trysnapshot
Fixed in CVS: http://bugs.php.net/fix.php?id=19160&r=fixedcvs
Fixed in release: http://bugs.php.net/fix.php?id=19160&r=alreadyfixed
Need backtrace: http://bugs.php.net/fix.php?id=19160&r=needtrace
Try newer version: http://bugs.php.net/fix.php?id=19160&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=19160&r=support
Expected behavior: http://bugs.php.net/fix.php?id=19160&r=notwrong
Not enough info: http://bugs.php.net/fix.php?id=19160&r=notenoughinfo
Submitted twice: http://bugs.php.net/fix.php?id=19160&r=submittedtwice
register_globals: http://bugs.php.net/fix.php?id=19160&r=globals