Sec Bug->Bug #81745 [Opn->Dup]: parse_url return wrong host if

From: Date: Thu, 19 Jan 2023 12:49:23 +0000
Subject: Sec Bug->Bug #81745 [Opn->Dup]: parse_url return wrong host if
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-243500@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81745&edit=1

 ID:                 81745
 Updated by:         cmb@php.net
 Reported by:        bengit at protonmail dot com
 Summary:            parse_url return wrong host if
-Status:             Open
+Status:             Duplicate
-Type:               Security
+Type:               Bug
 Package:            *URL Functions
 Operating System:   UNIX/Windows
 PHP Version:        8.2.1
-Assigned To:        
+Assigned To:        cmb
 Block user comment: N
 Private report:     Y

 New Comment:

> This is a security concern because parse_url is used to validate
> URL

Right.  This is exactly the problem; from the docs[1]:

| This function is not meant to validate the given URL, […]

and particularly:

| This function may not give correct results for relative or
| invalid URLs, and the results may not even match common behavior
| of HTTP clients. If URLs from untrusted input need to be parsed,
| extra validation is required, e.g. by using filter_var() with the
| FILTER_VALIDATE_URL filter.

However, filter_var($url) returns false, so PHP regards this URL
as invalid, and your application should reject it.

That said, parse_url() leaves a lot to be desired, but it is
almost impossible to change its behavior, because some code relies
on arbitrary observable behavior of that function (I fixed a
respective issue a while ago, but that had to be reverted due to
user relying on the broken behavior).

And although the issue is somewhat different I'm closing this as
duplicate of <https://github.com/php/php-src/issues/7890>.

[1] <https://www.php.net/parse_url>


Previous Comments:
------------------------------------------------------------------------
[2023-01-16 14:54:48] bengit at protonmail dot com

Just update my email

------------------------------------------------------------------------
[2023-01-16 14:31:29] bengit at protonmail dot com

Description:
------------
The function parse_url wrongly handle backslash "\" in URL username.

If you try to call parse_url on URL with a value like: 
"//example.com\@google.com"

"host" value will be "google.com" and username "example.com\" 
Whereas browser (Chrome/Firefox at least) will consider "example.com" as the domain and
"@google.com as the path

Tested as a HTML link href and has a HTTP "Header location", on both case, the browser
considere the domain as "example.com"

This works with all scheme http,https and //

The RFC 3986 do not deals how to exactly handle backslash value.
But we can assume that handling URL like major browser should be the way to do.
They seems to replace backslash by slash.

This is a security concern because parse_url is used to validate URL and a value injection could
lead in wrong host detection.

This vulnerability is already actively used - I found some attempts into my server logs.

Can reproduce the issue on 7.4.3 (Unix) / 8.1.2 (Windows) / 8.2.1 (MacOS) 


Test script:
---------------
<?php

$url = '//example.com\@google.com';

var_dump($url);

// Here the domain displayed is "google.com"
var_dump(parse_url($url));

// Click and you will be redirected to "example.com"
?><a href="<?= $url; ?>" target="_blank">Test URL in a
browser</a>

Expected result:
----------------
Parsing should return false or example.com in the domain and "@google.com" as a path



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=81745&edit=1


Thread (1 message)

  • cmb@php.net
  • Unknown Message
    • cmb@php.net
« previous php.bugs (#243500) next »