Edit report at https://bugs.php.net/bug.php?id=80385&edit=1
ID: 80385
Comment by: 306503207 at qq dot com
Reported by: 306503207 at qq dot com
Summary: Response data preceded by post data
Status: Open
Type: Bug
Package: FPM related
Operating System: CentOS 7.4
PHP Version: 7.2.34
Block user comment: N
Private report: N
New Comment:
How to configure PHP FPM pool security
Previous Comments:
------------------------------------------------------------------------
[2020-11-24 04:20:21] 306503207 at qq dot com
æ£æµå°ä¸æ(ç®ä½)
è±è¯
éç¨é¢å
çç©å»è¯
I think PHP was attacked. I can reproduce this situation. For example, by using nginx, the
configuration parameters can modify the PHP configuration. The configuration is as follows:
#fastcgi_param PHP_VALUE "auto_prepend_file= php://input \n auto_append_file= php://input
";
#fastcgi_param PHP_ADMIN_VALUE "allow_url_include=On";
How can I close PHP_ADMIN_VALUE of parameter?
------------------------------------------------------------------------
[2020-11-23 23:51:35] dano at fashionphile dot com
We are getting the exact same problem since 11/13/2020 we have started getting the exact same issue.
We are on php 7.3.24 currently. We have narrowed this issue down to only post requests and whenever
we restart PHP-fpm it solves the issue for about an hour of time, then continues again.
------------------------------------------------------------------------
[2020-11-23 19:43:02] shoebox at dnbradio dot com
re: phpinfo() -- yes I did a diff on the full phpinfo() output. I trimmed it down in my previous
post so that it would fit within a single screenshot.
re: hack, I thought the same thing; but given that this is an isolated freshly built container I am
thinking that's not the case. I've setup firewall so that no outside traffic besides my
own IP can hit the server but the issue still reoccurred. I will try testing on a local machine
deployment as well from a freshly built container.
re:pools -- no additional pool configuration is added. There is only a single app running on this
container and running on this host. I'll look further into this.
------------------------------------------------------------------------
[2020-11-23 19:06:54] requinix@php.net
This may very well be my imagination getting the best of me, but seeing a configuration with
allow_url_include=on and auto_prepend_file=input, that's the sort of thing I would attribute to
a hack. Because with those enabled, someone can run PHP code on your server without having to
compromise any application files. Though there is normally some sort of trigger to get that behavior
- it randomly happening would break stuff and draw attention to the problem.
Have you looked into that sort of possibility? Do you have access logs you can check to see if
there's anything suspicious? Are your php-fpm pools configured securely? Any unauthorized file
changes?
And when you compared phpinfo outputs, did you compare the *entire* output? Everything from the
configure command to the extension settings?
------------------------------------------------------------------------
[2020-11-23 18:39:21] shoebox at dnbradio dot com
I'm now wondering if this could be caused by a bug in one of the php modules so I am disabling
them for now. I suspect this could be caused by the mongo module since the OP mentioned something
mongo-related in their original report. Here is my Docker file showing all modules I have currently
enabled. I will disable all of these to see if the problem persists.
FROM php:7.4-fpm
RUN apt-get update && apt-get install -y \
libfreetype6-dev \
libssl-dev \
libpng-dev \
libjpeg62-turbo-dev \
libmcrypt-dev \
libmagickwand-dev --no-install-recommends \
zip \
unzip \
git-all \
libaspell-dev \
mariadb-client --no-install-recommends \
&& docker-php-ext-install pdo_mysql \
&& pecl install imagick \
&& docker-php-ext-enable imagick \
&& docker-php-ext-configure gd \
--with-freetype \
--with-jpeg \
&& docker-php-ext-install -j$(nproc) gd \
&& pecl install mongodb \
&& docker-php-ext-enable mongodb \
&& pecl install mailparse \
&& docker-php-ext-enable mailparse
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=80385
--
Edit this bug report at https://bugs.php.net/bug.php?id=80385&edit=1