CurlSslServerSpoofing
error on by defaultGroup: Security · PhpStorm name: CurlSslServerSpoofingInspection
Turning off cURL's TLS peer or host-name verification (CURLOPT_SSL_VERIFYPEER, CURLOPT_SSL_VERIFYHOST) lets anyone in the middle impersonate the server. Report places where these options are set to a disabling value.
Example
php
<?php
function fetch($handle, $insecure)
{
curl_setopt($handle, CURLOPT_SSL_VERIFYHOST, 1);
curl_setopt($handle, CURLOPT_SSL_VERIFYPEER, FALSE);
curl_setopt($handle, CURLOPT_SSL_VERIFYHOST, $insecure ? 0 : '1');
curl_setopt($handle, CURLOPT_SSL_VERIFYHOST, $insecure ? 0 : 2);
curl_setopt($handle, CURLOPT_SSL_VERIFYPEER, '1');
$peer = null;
curl_setopt_array($handle, [
CURLOPT_TIMEOUT => 5,
CURLOPT_SSL_VERIFYPEER => $peer,
CURLOPT_SSL_VERIFYHOST => "2",
]);
$conf = [];
$conf['tls'][CURLOPT_SSL_VERIFYHOST] = true;
$conf[CURLOPT_SSL_VERIFYPEER] = true;
return $conf;
}Reported:
- line 4: Host name verification is disabled; keep CURLOPT_SSL_VERIFYHOST at 2.
- line 5: Peer certificate verification is disabled; keep CURLOPT_SSL_VERIFYPEER enabled.
- line 6: Host name verification is disabled; keep CURLOPT_SSL_VERIFYHOST at 2.
- line 13: Peer certificate verification is disabled; keep CURLOPT_SSL_VERIFYPEER enabled.
- line 18: Host name verification is disabled; keep CURLOPT_SSL_VERIFYHOST at 2.
Configure
In custos.json:
json
{
"rules": {
"CurlSslServerSpoofing": {
"enabled": false
}
}
}Suppress
Before the statement or declaration (or the first statement of the file), either of:
php
// @custos-ignore CurlSslServerSpoofing
/**
* @noinspection CurlSslServerSpoofingInspection
*/