Bug #66600 [Opn]: FPM Module is Exposed in URL (/fcgi-php-fpm/)
| From: | hansv at senseofsecurity dot com dot au | Date: | Wed, 29 Jan 2014 02:49:29 +0000 |
| Subject: | Bug #66600 [Opn]: FPM Module is Exposed in URL (/fcgi-php-fpm/) | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-184063@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=66600&edit=1
ID: 66600
User updated by: hansv at senseofsecurity dot com dot au
Reported by: hansv at senseofsecurity dot com dot au
Summary: FPM Module is Exposed in URL (/fcgi-php-fpm/)
Status: Open
Type: Bug
Package: FPM related
Operating System: Debian
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
It appears that this is an Apache "feature" and not a PHP problem most likely.
Response from Apache:
"Every request to /fcgi-php-fpm is mapped to something that doesn't exist on disk (by the
Alias directive), so no <Directory> or <Files> configuration is applicable."
Previous Comments:
------------------------------------------------------------------------
[2014-01-29 00:01:50] hansv at senseofsecurity dot com dot au
Description:
------------
When a file is requested on a website by a user, it is normally done as follows:
http://127.0.0.1/somefile.php
During a review of logs, it was discovered that the same file can be called:
http://127.0.0.1/fcgi-php-fpm/somefile.php
Which confirms that FCGI is in use.
Furthermore, some misconfigurations may allow the user or an attacker to access files outside the
document root as follows:
http://127.0.0.1/fcgi-php-fpm/home/v1234567890/html/somefile.php
Where "/home/v1234567890/html/" is an example of a shared hosting URL. (This was
confirmed.)
Can you please look into this if it's an unknown bug or feature that you can't disable?
(It looks like a feature.)
If it's a known feature that you can disable, is it possible to disable in the PHP FPM
configuration files? And if so, how/where?
Version used: 5.4.4-14+deb7u5
(Latest Debian version package)
---
From manual page: http://www.php.net/install.fpm
---
Test script:
---------------
Please see description.
Expected result:
----------------
When the "/fcgi-php-fpm/" path is included in the URL, and a PHP file executes as it
should it is revealed that PHP FPM is in use even though all other headers and filenames may have
been removed.
Furthermore, in some shared hosting cases, it is possible to access files below the "document
root" for that user and possibly other users, depending on how severe an "access control
misconfiguration" is.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=66600&edit=1