Sec Bug->Req #64103 [Opn]: Bypass PHP Security Settings with PHP-FPM

From: Date: Sat, 04 Dec 2021 18:17:03 +0000
Subject: Sec Bug->Req #64103 [Opn]: Bypass PHP Security Settings with PHP-FPM
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-238168@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=64103&edit=1 ID: 64103 Updated by: bukka@php.net Reported by: wofeiwo at 80sec dot com Summary: Bypass PHP Security Settings with PHP-FPM Status: Open -Type: Security +Type: Feature/Change Request Package: FPM related Operating System: All PHP Version: master-Git-2013-01-30 (Git) Block user comment: N Private report: Y New Comment: This is well known and it's on purpose and there are already requests about this so nothing secret about it. I will keep it open as feature request until planned mitigations (e.g. configurable disabling of PHP_ADMIN_VALUE is implemented). Previous Comments: ------------------------------------------------------------------------ [2021-07-12 16:11:22] cmb@php.net This looks closely related to bug #77190, and is likely not a security issue. ------------------------------------------------------------------------ [2013-01-31 01:24:25] wofeiwo at 80sec dot com hi fat, what I mean is, clouds(or other shared hosts) dont need to expose FPM to the internet, and hacker dont need exposed FPM either. He just upload a script to the sandbox and use it connecting 127.0.0.1:9000 to break the jail(disable security settings). ------------------------------------------------------------------------ [2013-01-30 17:44:48] fat@php.net Even if I don't understand why a person of sound mind would expose FPM to the internet (don't tell me it's because of the cloud, if that's the case, stop using clouds: it's not secure !), there's some case where this could be a security risk, I agree. How to fix this: 1- add an option to php-fpm to disable the PHP_VALUE and PHP_ADMIN_VALUE fastcgi headers (default to disable). 2- see if we can find a way of authenticate the client (the legitimate webserver) (is there a way from a php script to see the content of the fastcgi request headers ?, if not, the legitimate webserver can sent a password in the fastcgi headers to authenticate itself to FPM) 3- both (1 & 2) 4- no ideas left for now ------------------------------------------------------------------------ [2013-01-30 09:36:59] laruence@php.net I think this is really a security issue. fat, what do you think? ------------------------------------------------------------------------ [2013-01-30 09:36:59] laruence@php.net I think this is really a security issue. fat, what do you think? ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=64103 -- Edit this bug report at https://bugs.php.net/bug.php?id=64103&edit=1

« previous php.bugs (#238168) next »