Bug #75356 [NEW]: parse_url filtering does not match CURL filtering
| From: | mattshockl at gmail dot com | Date: | Tue, 10 Oct 2017 18:39:01 +0000 |
| Subject: | Bug #75356 [NEW]: parse_url filtering does not match CURL filtering | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-211616@lists.php.net to get a copy of this message | ||
From: mattshockl at gmail dot com
Operating system: Linux
PHP version: 7.1.10
Package: Filter related
Bug Type: Bug
Bug description:parse_url filtering does not match CURL filtering
Description:
------------
Similarly to https://bugs.php.net/bug.php?id=73192, parse_url
parsing
mismatches the parsing of the curl module. By crafting a special url
like "badwebsite.com:/secrets.php", parse_url will parse and return
"badwebsite.com" as the schema, while curl will execute with
"badwebsite.com" as the hostname. For sites filtering on parse_url
hostname, this could be seen as a security issue/bypass. See the test
script for an example.
Test script:
---------------
$blacklist = array("google.com", "badwebsite.com");
$url = $_GET['url']; /* url=badwebsite.com:/secrets.php */
$parsed = parse_url($url);
if (isset($parsed['host']) && in_array($parsed['host'], $blacklist))
{
echo "bad hacker";
exit();
}
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, $url);
curl_setopt($ch, CURLOPT_COOKIE, "nuke_launch_codes=31-133-37");
curl_exec($ch);
curl_close($ch);
Expected result:
----------------
With url=badwebsite.com:/secrets.php, the expected result should be "bad
hacker."
Actual result:
--------------
With url=badwebsite.com:/secrets.php, the actual result is the HTML of
badwebsite.com/secrets.php
--
Edit bug report at https://bugs.php.net/bug.php?id=75356&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=75356&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=75356&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=75356&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=75356&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=75356&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=75356&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=75356&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=75356&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=75356&r=support
Expected behavior: https://bugs.php.net/fix.php?id=75356&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=75356&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=75356&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=75356&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=75356&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=75356&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=75356&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=75356&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=75356&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=75356&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=75356&r=mysqlcfg