Bug #75356 [NEW]: parse_url filtering does not match CURL filtering

From: Date: Tue, 10 Oct 2017 18:39:01 +0000
Subject: Bug #75356 [NEW]: parse_url filtering does not match CURL filtering
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-211616@lists.php.net to get a copy of this message
From: mattshockl at gmail dot com Operating system: Linux PHP version: 7.1.10 Package: Filter related Bug Type: Bug Bug description:parse_url filtering does not match CURL filtering Description: ------------ Similarly to https://bugs.php.net/bug.php?id=73192, parse_url parsing mismatches the parsing of the curl module. By crafting a special url like "badwebsite.com:/secrets.php", parse_url will parse and return "badwebsite.com" as the schema, while curl will execute with "badwebsite.com" as the hostname. For sites filtering on parse_url hostname, this could be seen as a security issue/bypass. See the test script for an example. Test script: --------------- $blacklist = array("google.com", "badwebsite.com"); $url = $_GET['url']; /* url=badwebsite.com:/secrets.php */ $parsed = parse_url($url); if (isset($parsed['host']) && in_array($parsed['host'], $blacklist)) { echo "bad hacker"; exit(); } $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, $url); curl_setopt($ch, CURLOPT_COOKIE, "nuke_launch_codes=31-133-37"); curl_exec($ch); curl_close($ch); Expected result: ---------------- With url=badwebsite.com:/secrets.php, the expected result should be "bad hacker." Actual result: -------------- With url=badwebsite.com:/secrets.php, the actual result is the HTML of badwebsite.com/secrets.php -- Edit bug report at https://bugs.php.net/bug.php?id=75356&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=75356&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=75356&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=75356&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=75356&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=75356&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=75356&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=75356&r=needscript Try newer version: https://bugs.php.net/fix.php?id=75356&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=75356&r=support Expected behavior: https://bugs.php.net/fix.php?id=75356&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=75356&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=75356&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=75356&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=75356&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=75356&r=dst IIS Stability: https://bugs.php.net/fix.php?id=75356&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=75356&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=75356&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=75356&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=75356&r=mysqlcfg

« previous php.bugs (#211616) next »