Bug #81680 [Com]: CR-LF injection via "From" field from ini setting
Edit report at https://bugs.php.net/bug.php?id=81680&edit=1
ID: 81680
Comment by: ramhani14256 at gmail dot com
Reported by: ive_jihwan at zerocution dot com
Summary: CR-LF injection via "From" field from ini setting
Status: Verified
Type: Bug
Package: PHP options/info functions
Operating System: *
PHP Version: 8.1.0
Block user comment: N
Private report: N
New Comment:
Yeah, by the reasoning from bug #81518, this is a bug. PHP Copyright © 2001-2022 The PHP Group
All rights reserved.
<https://www.dnahrblock.net/>github.com
Previous Comments:
------------------------------------------------------------------------
[2021-12-01 10:22:37] cmb@php.net
Yeah, by the reasoning from bug #81518, this is a bug.
------------------------------------------------------------------------
[2021-12-01 02:46:33] ive_jihwan at zerocution dot com
Change a bug package (referred #81518)
------------------------------------------------------------------------
[2021-12-01 02:44:34] ive_jihwan at zerocution dot com
Description:
------------
When we set "From" field by setting ini setting "from", which is used for
"ftp" and "http" file wrapper, it can inject an arbitrary string in the raw
socket message.
Since the injected string can contain CR-LF sequence(\r\n), this can be used to interrupt the flow
of FTP stream or injecting/smuggling an outgoing HTTP request.
I attached an accepted message using netcat in listening mode (nc -l)
This is caused by missing checking CNTRLs in both of http_fopen_wrapper.c and ftp_fopen_wrapper.c
-- ftp_fopen_wrapper.c:266 --
php_stream_printf(stream, "PASS %s\r\n", FG(from_address));
must be checked using PHP_FTP_CNTRL_CHK before calling printf
and
-- http_fopen_wrapper.c:550 --
smart_str_appends(&req_buf, FG(from_address));
also must be checked with some logic before appending
Test script:
---------------
<?php
ini_set("from", "Hi\r\nInjected: I HAVE IT");
file_get_contents("http://localhost:3500");
Expected result:
----------------
Should be failed
Actual result:
--------------
Listening on 0.0.0.0 3500
Connection received on 127.0.0.1 38882
GET / HTTP/1.1
From: Hi
Injected: I HAVE IT
Host: localhost:3500
Connection: close
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=81680&edit=1
Thread (8 messages)