Bug #80385 [Com]: Response data preceded by post data

From: Date: Tue, 01 Dec 2020 22:21:42 +0000
Subject: Bug #80385 [Com]: Response data preceded by post data
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-230777@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80385&edit=1

 ID:                 80385
 Comment by:         maxime dot mazouth-laurol at hotmail dot fr
 Reported by:        306503207 at qq dot com
 Summary:            Response data preceded by post data
 Status:             Open
 Type:               Bug
 Package:            FPM related
 Operating System:   CentOS 7.4
 PHP Version:        7.2.34
 Block user comment: N
 Private report:     N

 New Comment:

Did someone find a solution for this issue ? 
I have the same with php:7.2-fpm docker container named "engine" from now on.

Even if the POST data prepends the response, I keep getting none values from php.ini :
* linux command : docker-compose exec engine php -i | grep prepend
* output        : auto_prepend_file => no value => no value

* linux command : docker-compose exec engine php -i | grep url_include
* output        : allow_url_include => Off => Off


Previous Comments:
------------------------------------------------------------------------
[2020-11-24 04:25:23] 306503207 at qq dot com

How to configure PHP FPM pool security

------------------------------------------------------------------------
[2020-11-24 04:20:21] 306503207 at qq dot com

检测到中文(简体)
英语
通用领域
生物医药

I think PHP was attacked. I can reproduce this situation. For example, by using nginx, the
configuration parameters can modify the PHP configuration. The configuration is as follows:

#fastcgi_param PHP_VALUE "auto_prepend_file= php://input \n auto_append_file= php://input
";

#fastcgi_param PHP_ADMIN_VALUE "allow_url_include=On";

How can I close PHP_ADMIN_VALUE of parameter?

------------------------------------------------------------------------
[2020-11-23 23:51:35] dano at fashionphile dot com

We are getting the exact same problem since 11/13/2020 we have started getting the exact same issue.
We are on php 7.3.24 currently. We have narrowed this issue down to only post requests and whenever
we restart PHP-fpm it solves the issue for about an hour of time, then continues again.

------------------------------------------------------------------------
[2020-11-23 19:43:02] shoebox at dnbradio dot com

re: phpinfo() -- yes I did a diff on the full phpinfo() output. I trimmed it down in my previous
post so that it would fit within a single screenshot.

re: hack, I thought the same thing; but given that this is an isolated freshly built container I am
thinking that's not the case. I've setup firewall so that no outside traffic besides my
own IP can hit the server but the issue still reoccurred. I will try testing on a local machine
deployment as well from a freshly built container. 

re:pools -- no additional pool configuration is added. There is only a single app running on this
container and running on this host. I'll look further into this.

------------------------------------------------------------------------
[2020-11-23 19:06:54] requinix@php.net

This may very well be my imagination getting the best of me, but seeing a configuration with
allow_url_include=on and auto_prepend_file=input, that's the sort of thing I would attribute to
a hack. Because with those enabled, someone can run PHP code on your server without having to
compromise any application files. Though there is normally some sort of trigger to get that behavior
- it randomly happening would break stuff and draw attention to the problem.

Have you looked into that sort of possibility? Do you have access logs you can check to see if
there's anything suspicious? Are your php-fpm pools configured securely? Any unauthorized file
changes?

And when you compared phpinfo outputs, did you compare the *entire* output? Everything from the
configure command to the extension settings?

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=80385


--
Edit this bug report at https://bugs.php.net/bug.php?id=80385&edit=1


Thread (53 messages)

« previous php.bugs (#230777) next »