A CGI application vulnerability, CERT VU#797896

Status
Not open for further replies.

zEitEr

Super Moderator
Joined
Apr 11, 2005
Messages
15,405
Location
www.poralix.com
for PHP, Go, Python and others

httpoxy is a set of vulnerabilities that affect application code running in CGI, or CGI-like environments. It comes down to a simple namespace conflict:

  • RFC 3875 (CGI) puts the HTTP Proxy header from a request into the environment variables as HTTP_PROXY
  • HTTP_PROXY is a popular environment variable used to configure an outgoing proxy
This leads to a remotely exploitable vulnerability. If you’re running PHP or CGI, you should block the Proxy header now.

https://httpoxy.org

Advisory: Apache Software Foundation Projects and "httpoxy" CERT VU#797896
Canonical URL: https://www.apache.org/security/asf-httpoxy-response.txt
Publication: v1.0 18 July 2016

NGINX:

Code:
fastcgi_param HTTP_PROXY "";

APACHE:

Code:
RequestHeader unset Proxy early
 
Status
Not open for further replies.
Back
Top