Skip to content

HostnameSubstitution ​

error on by default

Group: Security · PhpStorm name: HostnameSubstitutionInspection

$_SERVER['HTTP_HOST'] and $_SERVER['SERVER_NAME'] can be controlled by the client (Host header). Using them to build e-mail addresses or storing them in domain/host/email-like variables or properties without a whitelist check lets an attacker inject their own domain.

Example ​

php
<?php
$sender  = 'noreply@' . $_SERVER['HTTP_HOST'];
$bounce  = 'x' . 'bounce@' . trim($_SERVER["SERVER_NAME"]) . '.local';
$siteHost = $_SERVER['SERVER_NAME'];
$label   = 'Served by ' . $_SERVER['SERVER_NAME'];
$current = $_SERVER['HTTP_HOST'];

function contact()
{
    $base = strtolower($_SERVER['HTTP_HOST']);
    $base = str_replace('www.', '', $base);
    return 'help@' . $base;
}

function fallback()
{
    $base = $_SERVER['HTTP_HOST'];
    $base = 'example.org';
    return 'help@' . $base;
}

class Mailer
{
    public function configure()
    {
        $this->mailDomain = $_SERVER['HTTP_HOST'];
    }

    public function safe(array $known)
    {
        if (in_array($_SERVER['HTTP_HOST'], $known, true)) {
            $this->replyHost = $_SERVER['HTTP_HOST'];
        }
    }
}

Reported:

  • line 2: E-mail address built from client-controlled $_SERVER['HTTP_HOST']; validate it against a whitelist.
  • line 3: E-mail address built from client-controlled $_SERVER['SERVER_NAME']; validate it against a whitelist.
  • line 4: Client-controlled host name stored here; validate it against a whitelist.
  • line 12: E-mail address built from client-controlled $_SERVER['HTTP_HOST']; validate it against a whitelist.
  • line 26: Client-controlled host name stored here; validate it against a whitelist.

Configure ​

In custos.json:

json
{
  "rules": {
    "HostnameSubstitution": {
      "enabled": false
    }
  }
}

Suppress ​

Before the statement or declaration (or the first statement of the file), either of:

php
// @custos-ignore HostnameSubstitution

/**
 * @noinspection HostnameSubstitutionInspection
 */

Released under the MIT License. Rule catalogue modelled on Php Inspections (EA Extended); independent clean-room implementation.