Bug #80385 [Com]: Response data preceded by post data

From: Date: Sun, 21 Nov 2021 16:03:47 +0000
Subject: Bug #80385 [Com]: Response data preceded by post data
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-237898@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80385&edit=1

 ID:                 80385
 Comment by:         blissweb at hotmail dot com
 Reported by:        306503207 at qq dot com
 Summary:            Response data preceded by post data
 Status:             Re-Opened
 Type:               Bug
 Package:            FPM related
 Operating System:   CentOS 7.4
 PHP Version:        7.2.34
 Assigned To:        bukka
 Block user comment: N
 Private report:     N

 New Comment:

We have this issue.  Our FPM port is set to 9001, so its not related to 9000.   Centos 7.4.25
php-fpm  7.9 centos.  As others have said, the auto_prepend_file starts getting set on its own.


Previous Comments:
------------------------------------------------------------------------
[2021-04-29 13:34:56] nikic@php.net

I've been trying to reproduce this issue based on the instructions from en3py at hotmail dot
com, but wasn't able to. I'm not seeing any changes in phpinfo output after querying the
FPM status page.

------------------------------------------------------------------------
[2021-04-29 09:53:54] ahirsch29 at gmail dot com

Same problem with php 8.0.3 - raised the issue here: https://bugs.php.net/bug.php?id=80385

------------------------------------------------------------------------
[2021-04-29 08:39:43] requinix@php.net

Related To: Bug #81000

------------------------------------------------------------------------
[2021-03-29 16:41:32] raqooncoon at gmail dot com

I think this may be about 9000 port of php-fpm service. It must not be available from outside of
server, otherwise php-fpm will be vulnerable to sending TCP packets over bogus FastCGI protocol that
leads to execution of arbitrary code and changing running php config.
1) Try set
listen = 127.0.0.1:9000
inside www.conf of php-fpm.
2) Make sure that 9000 port is not opened, check ufw settings.
3) If you use docker, DO NOT EXPOSE 9000 port from php-fpm container. Use reverse-proxy nginx and
docker network for php-fpm to nginx connection.

Read more about this php-fpm vulnerability https://www.x1a0t.com/2020/02/04/Attack-php-fpm/

------------------------------------------------------------------------
[2021-03-22 17:56:24] en3py at hotmail dot com

The service is binded to 0.0.0.0 but it allows only connections from the monitoring server
(firewalled + access list).

The issue happens even if the service is binded on 127.0.0.1 and you make the call from the same
server.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=80385


--
Edit this bug report at https://bugs.php.net/bug.php?id=80385&edit=1


Thread (53 messages)

« previous php.bugs (#237898) next »