Bug #80385 [Com]: Response data preceded by post data

From: Date: Thu, 29 Apr 2021 09:53:54 +0000
Subject: Bug #80385 [Com]: Response data preceded by post data
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-233615@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80385&edit=1

 ID:                 80385
 Comment by:         ahirsch29 at gmail dot com
 Reported by:        306503207 at qq dot com
 Summary:            Response data preceded by post data
 Status:             Re-Opened
 Type:               Bug
 Package:            FPM related
 Operating System:   CentOS 7.4
 PHP Version:        7.2.34
 Assigned To:        bukka
 Block user comment: N
 Private report:     N

 New Comment:

Same problem with php 8.0.3 - raised the issue here: https://bugs.php.net/bug.php?id=80385


Previous Comments:
------------------------------------------------------------------------
[2021-04-29 08:39:43] requinix@php.net

Related To: Bug #81000

------------------------------------------------------------------------
[2021-03-29 16:41:32] raqooncoon at gmail dot com

I think this may be about 9000 port of php-fpm service. It must not be available from outside of
server, otherwise php-fpm will be vulnerable to sending TCP packets over bogus FastCGI protocol that
leads to execution of arbitrary code and changing running php config.
1) Try set
listen = 127.0.0.1:9000
inside www.conf of php-fpm.
2) Make sure that 9000 port is not opened, check ufw settings.
3) If you use docker, DO NOT EXPOSE 9000 port from php-fpm container. Use reverse-proxy nginx and
docker network for php-fpm to nginx connection.

Read more about this php-fpm vulnerability https://www.x1a0t.com/2020/02/04/Attack-php-fpm/

------------------------------------------------------------------------
[2021-03-22 17:56:24] en3py at hotmail dot com

The service is binded to 0.0.0.0 but it allows only connections from the monitoring server
(firewalled + access list).

The issue happens even if the service is binded on 127.0.0.1 and you make the call from the same
server.

------------------------------------------------------------------------
[2021-03-21 19:42:05] bukka@php.net

> listen = 0.0.0.0:17302

Is this is a publicly accessible server or protect by VPN? Just wondering if something else could
hit it with PHP_ADMIN_VALUE. It's definitely not a good idea to open it to the world though.
Did you try to use listen.allowed_clients and white list the nagios? Just wondering if it's
because of something hits that with PHP_ADMIN_VALUE or there's another issue?

------------------------------------------------------------------------
[2021-03-19 17:40:47] en3py at hotmail dot com

Found the issue and full procedure to reproduce the problem.

We checked this behavior on:
- PHP 7.2.34
- PHP 7.3.26

We were using a Nagios control process to see if the FPM daemon was working, every 15 seconds it
made a POST call to the /status entry point of each context.

listen = 0.0.0.0:17302
pm.status_path = /status

1. Service started: the PHP-FPM worker works properly without any issue. POST requests were
correctly handled, data was not altered.

2. The Nagios control queried the /status page. This was the response:

[root@mon01 hosts]# /opt/nagios/libexec/check_fpm -p 17302 staging.eu.rightschain.co
"/status"
OK: PHP/7.3.26, pool [poolname] active processes 1 idle processes 1 started on 19/Mar/2021:17:31:45
+0000

3. The behavior of the two directives changed (in the phpinfo() output, not the configuration file)

FROM:

allow_url_include Off
auto_prepend_file None

TO:

allow_url_include On
auto_prepend_file php://input

And flapped between the two values resulting in an unstable behavior.

4. Restart the PHP-FPM process, and repeat from step 1. Occurs 100% of the times.

We disabled the /status page and binded the worker to 127.0.0.1 and changed monitoring process. The
issue disappeared from all monitored hosts.

For the record, this is the check we were using for the FastCGI gateway:
https://github.com/wuyunfeng/Python-FastCGI-Client

Hope it may be of help for anyone out there.

Cheers

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=80385


--
Edit this bug report at https://bugs.php.net/bug.php?id=80385&edit=1


Thread (53 messages)

« previous php.bugs (#233615) next »