Sec Bug->Req #64103 [Opn]: Bypass PHP Security Settings with PHP-FPM
| From: | bukka@php.net | Date: | Sat, 04 Dec 2021 18:17:03 +0000 |
| Subject: | Sec Bug->Req #64103 [Opn]: Bypass PHP Security Settings with PHP-FPM | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-238168@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=64103&edit=1
ID: 64103
Updated by: bukka@php.net
Reported by: wofeiwo at 80sec dot com
Summary: Bypass PHP Security Settings with PHP-FPM
Status: Open
-Type: Security
+Type: Feature/Change Request
Package: FPM related
Operating System: All
PHP Version: master-Git-2013-01-30 (Git)
Block user comment: N
Private report: Y
New Comment:
This is well known and it's on purpose and there are already requests about this so nothing
secret about it. I will keep it open as feature request until planned mitigations (e.g. configurable
disabling of PHP_ADMIN_VALUE is implemented).
Previous Comments:
------------------------------------------------------------------------
[2021-07-12 16:11:22] cmb@php.net
This looks closely related to bug #77190, and is likely not a
security issue.
------------------------------------------------------------------------
[2013-01-31 01:24:25] wofeiwo at 80sec dot com
hi fat, what I mean is, clouds(or other shared hosts) dont need to expose FPM to
the internet, and hacker dont need exposed FPM either. He just upload a script to
the sandbox and use it connecting 127.0.0.1:9000 to break the jail(disable
security settings).
------------------------------------------------------------------------
[2013-01-30 17:44:48] fat@php.net
Even if I don't understand why a person of sound mind would expose FPM to the
internet (don't tell me it's because of the cloud, if that's the case, stop
using clouds: it's not secure !), there's some case where this could be a
security risk, I agree.
How to fix this:
1- add an option to php-fpm to disable the PHP_VALUE and PHP_ADMIN_VALUE fastcgi
headers (default to disable).
2- see if we can find a way of authenticate the client (the legitimate
webserver) (is there a way from a php script to see the content of the fastcgi
request headers ?, if not, the legitimate webserver can sent a password in the
fastcgi headers to authenticate itself to FPM)
3- both (1 & 2)
4- no ideas left for now
------------------------------------------------------------------------
[2013-01-30 09:36:59] laruence@php.net
I think this is really a security issue. fat, what do you think?
------------------------------------------------------------------------
[2013-01-30 09:36:59] laruence@php.net
I think this is really a security issue. fat, what do you think?
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=64103
--
Edit this bug report at https://bugs.php.net/bug.php?id=64103&edit=1