Skip to content

CurlSslServerSpoofing ​

error on by default

Group: Security · PhpStorm name: CurlSslServerSpoofingInspection

Turning off cURL's TLS peer or host-name verification (CURLOPT_SSL_VERIFYPEER, CURLOPT_SSL_VERIFYHOST) lets anyone in the middle impersonate the server. Report places where these options are set to a disabling value.

Example ​

php
<?php
function fetch($handle, $insecure)
{
    curl_setopt($handle, CURLOPT_SSL_VERIFYHOST, 1);
    curl_setopt($handle, CURLOPT_SSL_VERIFYPEER, FALSE);
    curl_setopt($handle, CURLOPT_SSL_VERIFYHOST, $insecure ? 0 : '1');
    curl_setopt($handle, CURLOPT_SSL_VERIFYHOST, $insecure ? 0 : 2);
    curl_setopt($handle, CURLOPT_SSL_VERIFYPEER, '1');

    $peer = null;
    curl_setopt_array($handle, [
        CURLOPT_TIMEOUT => 5,
        CURLOPT_SSL_VERIFYPEER => $peer,
        CURLOPT_SSL_VERIFYHOST => "2",
    ]);

    $conf = [];
    $conf['tls'][CURLOPT_SSL_VERIFYHOST] = true;
    $conf[CURLOPT_SSL_VERIFYPEER] = true;
    return $conf;
}

Reported:

  • line 4: Host name verification is disabled; keep CURLOPT_SSL_VERIFYHOST at 2.
  • line 5: Peer certificate verification is disabled; keep CURLOPT_SSL_VERIFYPEER enabled.
  • line 6: Host name verification is disabled; keep CURLOPT_SSL_VERIFYHOST at 2.
  • line 13: Peer certificate verification is disabled; keep CURLOPT_SSL_VERIFYPEER enabled.
  • line 18: Host name verification is disabled; keep CURLOPT_SSL_VERIFYHOST at 2.

Configure ​

In custos.json:

json
{
  "rules": {
    "CurlSslServerSpoofing": {
      "enabled": false
    }
  }
}

Suppress ​

Before the statement or declaration (or the first statement of the file), either of:

php
// @custos-ignore CurlSslServerSpoofing

/**
 * @noinspection CurlSslServerSpoofingInspection
 */

Released under the MIT License. Rule catalogue modelled on Php Inspections (EA Extended); independent clean-room implementation.