Bug #72088 [Fbk->Asn]: file_get_contents() return empty in some urls
| From: | alejosimon at gmail dot com | Date: | Mon, 25 Apr 2016 12:33:30 +0000 |
| Subject: | Bug #72088 [Fbk->Asn]: file_get_contents() return empty in some urls | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-200763@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=72088&edit=1
ID: 72088
User updated by: alejosimon at gmail dot com
Reported by: alejosimon at gmail dot com
Summary: file_get_contents() return empty in some urls
-Status: Feedback
+Status: Assigned
Type: Bug
Package: HTTP related
Operating System: Windows 7 x64
PHP Version: 7.0.5
Assigned To: ab
Block user comment: N
Private report: N
New Comment:
I php x32 (5.6.20 and 5.6.20) work ok... only in x64 is the problem, and into win 7 x64 course.
Previous Comments:
------------------------------------------------------------------------
[2016-04-25 11:29:05] ab@php.net
@laruence, thanks for the ping. Yep, can reproduce.
It's in both 32 and 64-bit. But the investigation shows that it's likely a site
misconfiguration.
Here on Windows:
> curl.exe -V
curl 7.47.1 (x86_64-pc-win32) libcurl/7.47.1 OpenSSL/1.0.2g zlib/1.2.8 WinIDN libssh2/1.7.0
Protocols: dict file ftp ftps gopher http https imap imaps ldap pop3 pop3s rtsp scp sftp smtp smtps
telnet tftp
Features: AsynchDNS IDN IPv6 Largefile SSPI Kerberos SPNEGO NTLM SSL libz
> curl.exe -v -o /dev/null
>https://wswhomo.afip.gov.ar/wsfe/service.asmx?wsdl
.....
* Cipher selection: ALL:!EXPORT:!EXPORT40:!EXPORT56:!aNULL:!LOW:!RC4:@STRENGTH
* TLSv1.2 (OUT), TLS header, Certificate Status (22):
} [5 bytes data]
* TLSv1.2 (OUT), TLS handshake, Client hello (1):
} [512 bytes data]
* Unknown SSL protocol error in connection to wswhomo.afip.gov.ar:443
.....
Here on Jessie:
$ curl -V
curl 7.38.0 (x86_64-pc-linux-gnu) libcurl/7.38.0 OpenSSL/1.0.1k zlib/1.2.8 libidn/1.29 libssh2/1.4.3
librtmp/2.3
Protocols: dict file ftp ftps gopher http https imap imaps ldap ldaps pop3 pop3s rtmp rtsp scp sftp
smtp smtps telnet tftp
Features: AsynchDNS IDN IPv6 Largefile GSS-API SPNEGO NTLM NTLM_WB SSL libz TLS-SRP
$ curl -v -o /dev/null 'https://wswhomo.afip.gov.ar/wsfe/service.asmx?wsdl'
......
* SSLv3, TLS handshake, Client hello (1):
} [data not shown]
* SSLv3, TLS handshake, Server hello (2):
{ [data not shown]
* SSLv3, TLS handshake, CERT (11):
{ [data not shown]
* SSLv3, TLS handshake, Server finished (14):
{ [data not shown]
* SSLv3, TLS handshake, Client key exchange (16):
} [data not shown]
* SSLv3, TLS change cipher, Client hello (1):
} [data not shown]
* SSLv3, TLS handshake, Finished (20):
} [data not shown]
* SSLv3, TLS change cipher, Client hello (1):
{ [data not shown]
* SSLv3, TLS handshake, Finished (20):
{ [data not shown]
* SSL connection using TLSv1.0 / DES-CBC3-SHA
........
The latest OpenSSL release disables SSLv2 and many SSLv3 algorithms by default. Those can be enabled
by using extra configurations. The Windows builds however don't do it. The full info is
documented in the the latest security advisory https://openssl.org/news/secadv/20160301.txt
.
Notable in the Windows output is this line:
Cipher selection: ALL:!EXPORT:!EXPORT40:!EXPORT56:!aNULL:!LOW:!RC4:@STRENGTH
OpenSSL supports SSLv3 in my case on Jessie, the negotiation succeeds. The Windows variant tries to
negotiate right ahead with TLSv1.2, but the site seems to not to be ready for that. Ever more fun
that the target site is a goverment site that doesn't support the latest encryption :)
By the way, SSLv3 is already completely disabled since Fedora 23, so not even every Linux is
supposed to show expected (but have no Fedora at hand to test).
@alejosimon, to connect to the site it's enough to enforce TLSv1.0. You can create a stream
context for that.
Thanks.
------------------------------------------------------------------------
[2016-04-24 08:29:06] laruence@php.net
@welting, are you able to reproduce this?
------------------------------------------------------------------------
[2016-04-23 19:48:55] alejosimon at gmail dot com
Description:
------------
When I request via file_get_contents this URL:
$url = 'https://wswhomo.afip.gov.ar/wsfe/service.asmx?wsdl'
;
the response is empty, without errors. but some other URLs work ok.
BUT BUT this bug ONLY is present over Windows 64btis AND PHP_x64 build...
In linux and in both cases, Windows 32bits and/or PHP x32 always ok!
THE PROBLEM is only on PHP win64 versions.
Test script:
---------------
<?php
error_reporting( E_ALL );
ini_set( "display_errors", 1 );
$url = 'https://wswhomo.afip.gov.ar/wsfe/service.asmx?wsdl'
;
//$url = 'https://www.google.com.ar' ;
$response = file_get_contents( $url );
//print_r( $response ); // string empty
print_r( $http_response_header ); // array() empty
?>
Expected result:
----------------
Array
(
[0] => HTTP/1.1 200 OK
[1] => Connection: close
[2] => Date: Sat, 23 Apr 2016 19:43:24 GMT
[3] => Server: Microsoft-IIS/6.0
[4] => MicrosoftOfficeWebServer: 5.0_Pub
[5] => X-Powered-By: ASP.NET
[6] => X-AspNet-Version: 2.0.50727
[7] => Cache-Control: private, max-age=0
[8] => Content-Type: text/xml; charset=utf-8
[9] => Content-Length: 24646
)
// This result from PHP win32.
Actual result:
--------------
Array(
)
// This result from PHP win64.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=72088&edit=1