Bug #80385 [ReO]: Response data preceded by post data

From: Date: Thu, 29 Apr 2021 13:34:56 +0000
Subject: Bug #80385 [ReO]: Response data preceded by post data
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-233621@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80385&edit=1

 ID:                 80385
 Updated by:         nikic@php.net
 Reported by:        306503207 at qq dot com
 Summary:            Response data preceded by post data
 Status:             Re-Opened
 Type:               Bug
 Package:            FPM related
 Operating System:   CentOS 7.4
 PHP Version:        7.2.34
 Assigned To:        bukka
 Block user comment: N
 Private report:     N

 New Comment:

I've been trying to reproduce this issue based on the instructions from en3py at hotmail dot
com, but wasn't able to. I'm not seeing any changes in phpinfo output after querying the
FPM status page.


Previous Comments:
------------------------------------------------------------------------
[2021-04-29 09:53:54] ahirsch29 at gmail dot com

Same problem with php 8.0.3 - raised the issue here: https://bugs.php.net/bug.php?id=80385

------------------------------------------------------------------------
[2021-04-29 08:39:43] requinix@php.net

Related To: Bug #81000

------------------------------------------------------------------------
[2021-03-29 16:41:32] raqooncoon at gmail dot com

I think this may be about 9000 port of php-fpm service. It must not be available from outside of
server, otherwise php-fpm will be vulnerable to sending TCP packets over bogus FastCGI protocol that
leads to execution of arbitrary code and changing running php config.
1) Try set
listen = 127.0.0.1:9000
inside www.conf of php-fpm.
2) Make sure that 9000 port is not opened, check ufw settings.
3) If you use docker, DO NOT EXPOSE 9000 port from php-fpm container. Use reverse-proxy nginx and
docker network for php-fpm to nginx connection.

Read more about this php-fpm vulnerability https://www.x1a0t.com/2020/02/04/Attack-php-fpm/

------------------------------------------------------------------------
[2021-03-22 17:56:24] en3py at hotmail dot com

The service is binded to 0.0.0.0 but it allows only connections from the monitoring server
(firewalled + access list).

The issue happens even if the service is binded on 127.0.0.1 and you make the call from the same
server.

------------------------------------------------------------------------
[2021-03-21 19:42:05] bukka@php.net

> listen = 0.0.0.0:17302

Is this is a publicly accessible server or protect by VPN? Just wondering if something else could
hit it with PHP_ADMIN_VALUE. It's definitely not a good idea to open it to the world though.
Did you try to use listen.allowed_clients and white list the nagios? Just wondering if it's
because of something hits that with PHP_ADMIN_VALUE or there's another issue?

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=80385


--
Edit this bug report at https://bugs.php.net/bug.php?id=80385&edit=1


Thread (53 messages)

« previous php.bugs (#233621) next »