Bug #66600 [Opn]: FPM Module is Exposed in URL (/fcgi-php-fpm/)

From: Date: Wed, 29 Jan 2014 02:49:29 +0000
Subject: Bug #66600 [Opn]: FPM Module is Exposed in URL (/fcgi-php-fpm/)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-184063@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66600&edit=1 ID: 66600 User updated by: hansv at senseofsecurity dot com dot au Reported by: hansv at senseofsecurity dot com dot au Summary: FPM Module is Exposed in URL (/fcgi-php-fpm/) Status: Open Type: Bug Package: FPM related Operating System: Debian PHP Version: Irrelevant Block user comment: N Private report: N New Comment: It appears that this is an Apache "feature" and not a PHP problem most likely. Response from Apache: "Every request to /fcgi-php-fpm is mapped to something that doesn't exist on disk (by the Alias directive), so no <Directory> or <Files> configuration is applicable." Previous Comments: ------------------------------------------------------------------------ [2014-01-29 00:01:50] hansv at senseofsecurity dot com dot au Description: ------------ When a file is requested on a website by a user, it is normally done as follows: http://127.0.0.1/somefile.php During a review of logs, it was discovered that the same file can be called: http://127.0.0.1/fcgi-php-fpm/somefile.php Which confirms that FCGI is in use. Furthermore, some misconfigurations may allow the user or an attacker to access files outside the document root as follows: http://127.0.0.1/fcgi-php-fpm/home/v1234567890/html/somefile.php Where "/home/v1234567890/html/" is an example of a shared hosting URL. (This was confirmed.) Can you please look into this if it's an unknown bug or feature that you can't disable? (It looks like a feature.) If it's a known feature that you can disable, is it possible to disable in the PHP FPM configuration files? And if so, how/where? Version used: 5.4.4-14+deb7u5 (Latest Debian version package) --- From manual page: http://www.php.net/install.fpm --- Test script: --------------- Please see description. Expected result: ---------------- When the "/fcgi-php-fpm/" path is included in the URL, and a PHP file executes as it should it is revealed that PHP FPM is in use even though all other headers and filenames may have been removed. Furthermore, in some shared hosting cases, it is possible to access files below the "document root" for that user and possibly other users, depending on how severe an "access control misconfiguration" is. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=66600&edit=1

« previous php.bugs (#184063) next »