Edit report at https://bugs.php.net/bug.php?id=80385&edit=1
ID: 80385
Comment by: dklugmann2 at yahoo dot com
Reported by: 306503207 at qq dot com
Summary: Response data preceded by post data
Status: Re-Opened
Type: Bug
Package: FPM related
Operating System: CentOS 7.4
PHP Version: 7.2.34
Assigned To: bukka
Block user comment: N
Private report: N
New Comment:
Just a comment from our issue
This does appear to be 100% a hack attack exposing a php-fpm vulnerability
We updated the port in the php-fpm part of our yml docker file definition to be preceded with a
127.0.0.1 in front of the port name in the ports section thus restricting it to localhost access
only.
We also added a firewall with firewallcmd and limited access to only the very essential ports.
After that the issue has not reappeared.
Thanks
David
Previous Comments:
------------------------------------------------------------------------
[2021-11-23 23:37:05] dklugmann2 at yahoo dot com
Hi Jakub
I have emailed you our setup.
Many thanks for looking at this issue.
David
------------------------------------------------------------------------
[2021-11-23 21:34:12] bukka@php.net
Hi David,
It sounds good to me. If you could email me details how to recreate first, that would be awesome.
Ideally I would like to be able to recreate the issue locally on my computer because my setup will
make it easier for me to debug it. But if I'm not successful locally, then getting access to
the machine would be definitely useful. Mainly I would be then interested what is happening exactly
at time of the INI changes (e.g. having captured traffic of the port 9000 could be quite useful)
because after it changes, it's most likely too lite to see anything so in any case the steps to
recreate are very important.
Thanks
Jakub
------------------------------------------------------------------------
[2021-11-23 14:38:19] dklugmann2 at yahoo dot com
Hi Bukka
Thanks for responding. We would be very happy to work with you to get to the bottom of this issue.
We can send you the details to recreate the issue or alternatively what may be faster since it is
basically a new virtually empty VPS machine we could supply an example phpinfo page showing the
issue of the auto_prepend getting set periodically and we could provide you access details for our
machine also for any debugging you may want to try.
Please let us know what would be best for you.
Also our port 9000 is closed i just checked.
Thanks
David
------------------------------------------------------------------------
[2021-11-23 12:56:21] bukka@php.net
I meant as much details as possible about the environment will be helpful too.
------------------------------------------------------------------------
[2021-11-23 12:54:47] bukka@php.net
Is anyone able to provide reproducible steps that can lead to this problem in recreatable
environment?
If it's too difficult it could also help to use to analyze the traffic going to the instance
(e.g. using tcpdump or similar) and possibly checking if PHP_ADMIN_VALUE with auto_prepend_file can
be seen there.
In general as much as details about your environemnt setup would be helpful for futher
investigation.
Potentially I could also prepare a quick patch that will disable PHP_ADMIN_VALUE setting through
fcgi but would require someone who is experiencing the issue and is willing to compile and deploy
patched php-fpm to the server...
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=80385
--
Edit this bug report at https://bugs.php.net/bug.php?id=80385&edit=1