Bug #80385 [ReO]: Response data preceded by post data

From: Date: Fri, 26 Nov 2021 23:59:14 +0000
Subject: Bug #80385 [ReO]: Response data preceded by post data
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-238000@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80385&edit=1

 ID:                 80385
 Updated by:         bukka@php.net
 Reported by:        306503207 at qq dot com
 Summary:            Response data preceded by post data
 Status:             Re-Opened
 Type:               Bug
 Package:            FPM related
 Operating System:   CentOS 7.4
 PHP Version:        7.2.34
 Assigned To:        bukka
 Block user comment: N
 Private report:     N

 New Comment:

Just to repeat what was said before. This is not a vulnarebality but a feature that has been present
in PHP-FPM for some time. Personally I think it's not a really good thing to allow web servers
to change PHP ini through the FastCGI env variables and I plan to introduce an option to disable it.
But again it is on purpose and it is not a bug. There might be web server configs relaying on it so
we can't break it in minore release so the option would be an optional feature that you will
need to configure. We could maybe disable it by default in PHP 9.

Also I see in some comments confusion about the ports. It doesn't really matter what port
number PHP-FPM listen on. What matters is that this port is protected against external traffic (e.g.
by configuring firewall) and not exposed to anything else than your web server.

Please also note that even if we disable PHP_VALUE and PHP_ADMIN_VALUE, it's still not good
idea to allow external traffic to PHP-FPM. It wasn't designed for that and we would need to do
some additional review and hardening to be sure it's safe.


Previous Comments:
------------------------------------------------------------------------
[2021-11-26 14:09:13] dklugmann2 at yahoo dot com

Just a comment from our issue

This does appear to be 100% a hack attack exposing a php-fpm vulnerability

We updated the port in the php-fpm part of our yml docker file definition to be preceded with a
127.0.0.1 in front of the port name in the ports section thus restricting it to localhost access
only.

We also added a firewall with firewallcmd and limited access to only the very essential ports.

After that the issue has not reappeared.

Thanks

David

------------------------------------------------------------------------
[2021-11-23 23:37:05] dklugmann2 at yahoo dot com

Hi Jakub

I have emailed you our setup.

Many thanks for looking at this issue.

David

------------------------------------------------------------------------
[2021-11-23 21:34:12] bukka@php.net

Hi David,

It sounds good to me. If you could email me details how to recreate first, that would be awesome.
Ideally I would like to be able to recreate the issue locally on my computer because my setup will
make it easier for me to debug it. But if I'm not successful locally, then getting access to
the machine would be definitely useful. Mainly I would be then interested what is happening exactly
at time of the INI changes (e.g. having captured traffic of the port 9000 could be quite useful)
because after it changes, it's most likely too lite to see anything so in any case the steps to
recreate are very important.

Thanks

Jakub

------------------------------------------------------------------------
[2021-11-23 14:38:19] dklugmann2 at yahoo dot com

Hi Bukka

Thanks for responding. We would be very happy to work with you to get to the bottom of this issue.

We can send you the details to recreate the issue or alternatively what may be faster since it is
basically a new virtually empty VPS machine we could supply an example phpinfo page showing the
issue of the auto_prepend getting set periodically and we could provide you access details for our
machine also for any debugging you may want to try.

Please let us know what would be best for you.

Also our port 9000 is closed i just checked.

Thanks

David

------------------------------------------------------------------------
[2021-11-23 12:56:21] bukka@php.net

I meant as much details as possible about the environment will be helpful too.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=80385


--
Edit this bug report at https://bugs.php.net/bug.php?id=80385&edit=1


Thread (53 messages)

« previous php.bugs (#238000) next »