Bug #75356 [Opn->Nab]: parse_url filtering does not match CURL filtering
Edit report at https://bugs.php.net/bug.php?id=75356&edit=1
ID: 75356
Updated by: requinix@php.net
Reported by: mattshockl at gmail dot com
Summary: parse_url filtering does not match CURL filtering
-Status: Open
+Status: Not a bug
Type: Bug
-Package: Filter related
+Package: URL related
Operating System: Linux
PHP Version: 7.1.10
Block user comment: N
Private report: N
New Comment:
Thank you for taking the time to write to us, but this is not
a bug. Please double-check the documentation available at
http://www.php.net/manual/ and the instructions on how to
report
a bug at http://bugs.php.net/how-to-report.php
http://php.net/manual/en/function.parse-url.php
> This function is not meant to validate the given URL
http://php.net/manual/en/function.filter-var.php
Previous Comments:
------------------------------------------------------------------------
[2017-10-10 18:38:57] mattshockl at gmail dot com
Description:
------------
Similarly to https://bugs.php.net/bug.php?id=73192, parse_url
parsing mismatches the parsing of the curl module. By crafting a special url like
"badwebsite.com:/secrets.php", parse_url will parse and return "badwebsite.com"
as the schema, while curl will execute with "badwebsite.com" as the hostname. For sites
filtering on parse_url hostname, this could be seen as a security issue/bypass. See the test script
for an example.
Test script:
---------------
$blacklist = array("google.com", "badwebsite.com");
$url = $_GET['url']; /* url=badwebsite.com:/secrets.php */
$parsed = parse_url($url);
if (isset($parsed['host']) && in_array($parsed['host'], $blacklist))
{
echo "bad hacker";
exit();
}
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, $url);
curl_setopt($ch, CURLOPT_COOKIE, "nuke_launch_codes=31-133-37");
curl_exec($ch);
curl_close($ch);
Expected result:
----------------
With url=badwebsite.com:/secrets.php, the expected result should be "bad hacker."
Actual result:
--------------
With url=badwebsite.com:/secrets.php, the actual result is the HTML of badwebsite.com/secrets.php
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=75356&edit=1
Thread (2 messages)