Bug #81516 [Fbk->Nab]: Curl used with CURLOPT_WRITEFUNCTION rarely corrupts the response

From: Date: Thu, 14 Oct 2021 20:02:10 +0000
Subject: Bug #81516 [Fbk->Nab]: Curl used with CURLOPT_WRITEFUNCTION rarely corrupts the response
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-237198@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81516&edit=1

 ID:                 81516
 Updated by:         requinix@php.net
 Reported by:        roland at nextendweb dot com
 Summary:            Curl used with CURLOPT_WRITEFUNCTION rarely corrupts
                     the response
-Status:             Feedback
+Status:             Not a bug
 Type:               Bug
 Package:            cURL related
 PHP Version:        7.4.24
 Block user comment: N
 Private report:     N

 New Comment:

Thanks for finding that out!


Previous Comments:
------------------------------------------------------------------------
[2021-10-14 16:53:44] roland at nextendweb dot com

Imunify360 team confirmed this problem in their filters:

"Developers confirm that the Proactive Defence rule 10006 creates false positives and blocks
write operations. We are currently working on a solution.
Until the solution is available, please temporarily whitelist rule 10006 in Imunify360 >
Proactive Defense > Detected Events > Actions."

I think this bug can be closed.

------------------------------------------------------------------------
[2021-10-14 06:31:36] roland at nextendweb dot com

My latest finding that the common in these servers that all of them has a PHP module called i360
which is a security module developed by https://www.imunify360.com/

It seems like that their module identifies that given chunk as a threat. I get in touch with the
developer of that module and I will update this thread...

------------------------------------------------------------------------
[2021-10-13 23:19:39] requinix@php.net

Weird. What happens if you have PHP output the data instead and then pipe that into cat? Or use some
other methods of writing out to a file?

<?php
$value = '...';
echo substr(base64_decode($value), 0, 1100);
?>

$ php nowrite.php | cat > b.txt

------------------------------------------------------------------------
[2021-10-13 17:05:58] roland at nextendweb dot com

It looks like these are some kind of special systems which are unable to write the following data to
the filesystem and this is why that chunk is missing always.

https://gist.github.com/nextend/91b09c70a5a86fff34bcf87e29c9f068

Output is NULL and the file is not created in the filesystem. No error thrown.

------------------------------------------------------------------------
[2021-10-13 16:49:03] roland at nextendweb dot com

https://gist.github.com/nextend/8c0d752024bac9c0a030d5ba022dfac9

There is a chunk which is not written into the stream. The output is the following:
/ 1160
Chunk #4430: 781473d903bedf95d8a07d34974ac548 1160
Good md5: 231732259d67fe83ed6fc02d7ad9be57
Stream md5: 4a3b968a44c585a2883e687d61c251fb
Memory md5: 231732259d67fe83ed6fc02d7ad9be57

The return value of fwrite() for this chunk is NULL.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=81516


--
Edit this bug report at https://bugs.php.net/bug.php?id=81516&edit=1


Thread (14 messages)

« previous php.bugs (#237198) next »