Edit report at https://bugs.php.net/bug.php?id=80385&edit=1
ID: 80385
Comment by: ahirsch29 at gmail dot com
Reported by: 306503207 at qq dot com
Summary: Response data preceded by post data
Status: Re-Opened
Type: Bug
Package: FPM related
Operating System: CentOS 7.4
PHP Version: 7.2.34
Assigned To: bukka
Block user comment: N
Private report: N
New Comment:
Same problem with php 8.0.3 - raised the issue here: https://bugs.php.net/bug.php?id=80385
Previous Comments:
------------------------------------------------------------------------
[2021-04-29 08:39:43] requinix@php.net
Related To: Bug #81000
------------------------------------------------------------------------
[2021-03-29 16:41:32] raqooncoon at gmail dot com
I think this may be about 9000 port of php-fpm service. It must not be available from outside of
server, otherwise php-fpm will be vulnerable to sending TCP packets over bogus FastCGI protocol that
leads to execution of arbitrary code and changing running php config.
1) Try set
listen = 127.0.0.1:9000
inside www.conf of php-fpm.
2) Make sure that 9000 port is not opened, check ufw settings.
3) If you use docker, DO NOT EXPOSE 9000 port from php-fpm container. Use reverse-proxy nginx and
docker network for php-fpm to nginx connection.
Read more about this php-fpm vulnerability https://www.x1a0t.com/2020/02/04/Attack-php-fpm/
------------------------------------------------------------------------
[2021-03-22 17:56:24] en3py at hotmail dot com
The service is binded to 0.0.0.0 but it allows only connections from the monitoring server
(firewalled + access list).
The issue happens even if the service is binded on 127.0.0.1 and you make the call from the same
server.
------------------------------------------------------------------------
[2021-03-21 19:42:05] bukka@php.net
> listen = 0.0.0.0:17302
Is this is a publicly accessible server or protect by VPN? Just wondering if something else could
hit it with PHP_ADMIN_VALUE. It's definitely not a good idea to open it to the world though.
Did you try to use listen.allowed_clients and white list the nagios? Just wondering if it's
because of something hits that with PHP_ADMIN_VALUE or there's another issue?
------------------------------------------------------------------------
[2021-03-19 17:40:47] en3py at hotmail dot com
Found the issue and full procedure to reproduce the problem.
We checked this behavior on:
- PHP 7.2.34
- PHP 7.3.26
We were using a Nagios control process to see if the FPM daemon was working, every 15 seconds it
made a POST call to the /status entry point of each context.
listen = 0.0.0.0:17302
pm.status_path = /status
1. Service started: the PHP-FPM worker works properly without any issue. POST requests were
correctly handled, data was not altered.
2. The Nagios control queried the /status page. This was the response:
[root@mon01 hosts]# /opt/nagios/libexec/check_fpm -p 17302 staging.eu.rightschain.co
"/status"
OK: PHP/7.3.26, pool [poolname] active processes 1 idle processes 1 started on 19/Mar/2021:17:31:45
+0000
3. The behavior of the two directives changed (in the phpinfo() output, not the configuration file)
FROM:
allow_url_include Off
auto_prepend_file None
TO:
allow_url_include On
auto_prepend_file php://input
And flapped between the two values resulting in an unstable behavior.
4. Restart the PHP-FPM process, and repeat from step 1. Occurs 100% of the times.
We disabled the /status page and binded the worker to 127.0.0.1 and changed monitoring process. The
issue disappeared from all monitored hosts.
For the record, this is the check we were using for the FastCGI gateway:
https://github.com/wuyunfeng/Python-FastCGI-Client
Hope it may be of help for anyone out there.
Cheers
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=80385
--
Edit this bug report at https://bugs.php.net/bug.php?id=80385&edit=1