Edit report at https://bugs.php.net/bug.php?id=80385&edit=1
ID: 80385
Comment by: maxime dot mazouth-laurol at hotmail dot fr
Reported by: 306503207 at qq dot com
Summary: Response data preceded by post data
Status: Open
Type: Bug
Package: FPM related
Operating System: CentOS 7.4
PHP Version: 7.2.34
Block user comment: N
Private report: N
New Comment:
Did someone find a solution for this issue ?
I have the same with php:7.2-fpm docker container named "engine" from now on.
Even if the POST data prepends the response, I keep getting none values from php.ini :
* linux command : docker-compose exec engine php -i | grep prepend
* output : auto_prepend_file => no value => no value
* linux command : docker-compose exec engine php -i | grep url_include
* output : allow_url_include => Off => Off
Previous Comments:
------------------------------------------------------------------------
[2020-11-24 04:25:23] 306503207 at qq dot com
How to configure PHP FPM pool security
------------------------------------------------------------------------
[2020-11-24 04:20:21] 306503207 at qq dot com
æ£æµå°ä¸æ(ç®ä½)
è±è¯
éç¨é¢å
çç©å»è¯
I think PHP was attacked. I can reproduce this situation. For example, by using nginx, the
configuration parameters can modify the PHP configuration. The configuration is as follows:
#fastcgi_param PHP_VALUE "auto_prepend_file= php://input \n auto_append_file= php://input
";
#fastcgi_param PHP_ADMIN_VALUE "allow_url_include=On";
How can I close PHP_ADMIN_VALUE of parameter?
------------------------------------------------------------------------
[2020-11-23 23:51:35] dano at fashionphile dot com
We are getting the exact same problem since 11/13/2020 we have started getting the exact same issue.
We are on php 7.3.24 currently. We have narrowed this issue down to only post requests and whenever
we restart PHP-fpm it solves the issue for about an hour of time, then continues again.
------------------------------------------------------------------------
[2020-11-23 19:43:02] shoebox at dnbradio dot com
re: phpinfo() -- yes I did a diff on the full phpinfo() output. I trimmed it down in my previous
post so that it would fit within a single screenshot.
re: hack, I thought the same thing; but given that this is an isolated freshly built container I am
thinking that's not the case. I've setup firewall so that no outside traffic besides my
own IP can hit the server but the issue still reoccurred. I will try testing on a local machine
deployment as well from a freshly built container.
re:pools -- no additional pool configuration is added. There is only a single app running on this
container and running on this host. I'll look further into this.
------------------------------------------------------------------------
[2020-11-23 19:06:54] requinix@php.net
This may very well be my imagination getting the best of me, but seeing a configuration with
allow_url_include=on and auto_prepend_file=input, that's the sort of thing I would attribute to
a hack. Because with those enabled, someone can run PHP code on your server without having to
compromise any application files. Though there is normally some sort of trigger to get that behavior
- it randomly happening would break stuff and draw attention to the problem.
Have you looked into that sort of possibility? Do you have access logs you can check to see if
there's anything suspicious? Are your php-fpm pools configured securely? Any unauthorized file
changes?
And when you compared phpinfo outputs, did you compare the *entire* output? Everything from the
configure command to the extension settings?
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=80385
--
Edit this bug report at https://bugs.php.net/bug.php?id=80385&edit=1