Skip to content

573 - Check URLs are valid before attempting to perform HTTP request - #578

Open
markfullmer wants to merge 3 commits into
php-embed:masterfrom
markfullmer:573-valid-url
Open

markfullmer wants to merge 3 commits into
php-embed:masterfrom
markfullmer:573-valid-url

Conversation

@markfullmer

Copy link
Copy Markdown

Purpose

Resolves #573

Implementation

Adds a new isValidUrl() helper function that:

  • checks the URL using the standard PHP FILTER_VALIDATE_URL
  • checks IPs the host resolves to and uses dns_get_record() to check if a record exists
  • if dns_get_record() fails, try gethostbyname()
  • Filter any found IPs against PHP's reserved and privileged ranges (FILTER_FLAG_NO_PRIV_RANGE | FILTER_FLAG_NO_RES_RANGE)

This helper function is added to Extractor::resolveUri(), adjacent to the check for HTTP URLs.

Finally, the existing isHttp() function is updated to use a stricter "allow-list" methodology, rejecting anything that does not match the http or https schema, as suggested in #573.

Test coverage

Test coverage is added in FunctionsTest. All of its scenarios pass. There are other failing tests, but these are unchanged compared to the failing tests prior to this code change.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Possible SSRF Exploitation via Scheme Validation Bypass

2 participants