Bug #76566 [Opn->Nab]: curl fails to connect to the right host

From: Date: Tue, 03 Jul 2018 03:37:17 +0000
Subject: Bug #76566 [Opn->Nab]: curl fails to connect to the right host
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-216089@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76566&edit=1 ID: 76566 Updated by: requinix@php.net Reported by: a dot nadelle92 at gmail dot com Summary: curl fails to connect to the right host -Status: Open +Status: Not a bug Type: Bug -Package: HTTP related +Package: cURL related Operating System: Irrelevant PHP Version: 7.1Git-2018-07-02 (Git) Block user comment: N Private report: N New Comment: Chrome thinks your URL goes to google.com too. Edge refuses to follow a link with it for some unknown but probably stupid reason. The URL doesn't even look valid to me. So from where I stand, cURL is the odd one out. But we don't control cURL. You'll need to report the problem to them and see what they say about it. Previous Comments: ------------------------------------------------------------------------ [2018-07-02 19:35:50] a dot nadelle92 at gmail dot com Description: ------------ Hi, When putting this link http://jx$(Tqz*Rn9d~@www.example.com:+@www.google.com to parse_url() function, the host is www.google.com. Nevertheless, when trying to connect with curl it connects to www.example.com . I discovered this bug since I was able to bypass hostname filtering and I could do a Server Side Request Forgery. I tested version 7.1.18, I didn't test the latest one but I do not see a report for such bug. Perhaps, they may be vulnerable the same. Test script: --------------- <?php /** * Get a web file (HTML, XHTML, XML, image, etc.) from a URL. Return an * array containing the HTTP server response header fields and content. */ $url = "http://jx$(Tqz*Rn9d~@www.example.com:+@www.google.com"; var_dump(parse_url($url)); function get_web_page( $url ) { $user_agent='Mozilla/5.0 (Windows NT 6.1; rv:8.0) Gecko/20100101 Firefox/8.0'; $options = array( CURLOPT_CUSTOMREQUEST => "GET", //set request type post or get CURLOPT_POST => false, //set to GET CURLOPT_USERAGENT => $user_agent, //set user agent CURLOPT_RETURNTRANSFER => true, // return web page CURLOPT_HEADER => false, // don't return headers CURLOPT_FOLLOWLOCATION => true, // follow redirects CURLOPT_ENCODING => "", // handle all encodings CURLOPT_AUTOREFERER => false, // set referer on redirect CURLOPT_CONNECTTIMEOUT => 120, // timeout on connect CURLOPT_TIMEOUT => 120, // timeout on response CURLOPT_MAXREDIRS => 2, // stop after 10 redirects CURLOPT_HTTPHEADER => array("Cookie: ".base64_decode($_REQUEST['cookie'])) ); $ch = curl_init( $url ); curl_setopt_array( $ch, $options ); $content = curl_exec( $ch ); $err = curl_errno( $ch ); $errmsg = curl_error( $ch ); $header = curl_getinfo( $ch ); curl_close( $ch ); $header['errno'] = $err; $header['errmsg'] = $errmsg; $header['content'] = $content; return $header; } $result = get_web_page( $url ); if ( $result['errno'] != 0 ) { echo "strange_error ".$result['errno']; } if ( $result['http_code'] == 200 ) { echo $result['content']; } else { echo $result['http_code']; } ?> Expected result: ---------------- curl connecting to the same host as parse_url() function Actual result: -------------- curl is not connecting to the same host as parse_url() function ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=76566&edit=1

« previous php.bugs (#216089) next »