Bug #80385 [Com]: Response data preceded by post data

From: Date: Mon, 01 Mar 2021 07:52:47 +0000
Subject: Bug #80385 [Com]: Response data preceded by post data
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-232439@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80385&edit=1

 ID:                 80385
 Comment by:         camalolo at gmail dot com
 Reported by:        306503207 at qq dot com
 Summary:            Response data preceded by post data
 Status:             No Feedback
 Type:               Bug
 Package:            FPM related
 Operating System:   CentOS 7.4
 PHP Version:        7.2.34
 Assigned To:        bukka
 Block user comment: N
 Private report:     N

 New Comment:

Having the same exact issue. Php 7.3.27 / Ubuntu 20.04


Previous Comments:
------------------------------------------------------------------------
[2021-02-27 05:16:56] wjh08081329 at gmail dot com

when i run use docker php:8.0.1 ,i encounter this issue, but when i start a container with a self
defined php.ini locate in  /usr/local/etc/php/ which with auto_prepend_file is no value ,the issue
is gone

------------------------------------------------------------------------
[2021-02-09 14:28:44] benedikt dot schaller at simovative dot com

Same problem here with Ubuntu 16.04 and PHP7.3 over apache fast-cgi module and php-fpm. The problem
apears if the fpm service runs for some time and is gone after a php-fpm restart.

I think that is a big security issue, because you could execute php code.

We have a log of similiar systems and it only happens on one of them. There themes to be no
difference.

------------------------------------------------------------------------
[2021-01-10 04:22:09] php-bugs at lists dot php dot net

No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Re-Opened". Thank you.

------------------------------------------------------------------------
[2020-12-28 19:22:59] bukka@php.net

So this is specifically documented in https://www.php.net/manual/en/install.fpm.configuration.php
. See the "Example #2 set PHP settings in nginx.conf" and the warning below that
"php-fpm should not be bound to a worldwide accessible address". So if the FPM is publicly
available, it should at least have listen.allowed_clients set so only the server can connect to it.

This looks like the reason why this got reported (setting PHP_VALUE and PHP_ADMIN_VALUE) from the OP
comments. Does anyone see this behaviour when having fpm protected?

Also it's not the first time I'm seeing a report like this so I'm thinking to
introduce some options that would disallow this.

------------------------------------------------------------------------
[2020-12-09 11:28:22] shoebox at dnbradio dot com

This is not a fix to the bug report but this is how I am working around the issue.  I'm now
using nginx with mod_security enabled (wodby/nginx has mod_security built-in), and I have my default
host and location on nginx pointing to a static html page rather than php so that the attacker
cannot access the php location without using a domain name defined in the nginx config. With the
previous configuration an attacker was able to hit php-fpm by just going to the ip address. I have
not seen the problem return, however I am unsure if nginx with mod_security defaults is still
vulnerable to the same exploit. Additional configuration and filters may need to be applied.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=80385


--
Edit this bug report at https://bugs.php.net/bug.php?id=80385&edit=1


Thread (53 messages)

« previous php.bugs (#232439) next »