HostnameSubstitution
error on by defaultGroup: Security · PhpStorm name: HostnameSubstitutionInspection
$_SERVER['HTTP_HOST'] and $_SERVER['SERVER_NAME'] can be controlled by the client (Host header). Using them to build e-mail addresses or storing them in domain/host/email-like variables or properties without a whitelist check lets an attacker inject their own domain.
Example
php
<?php
$sender = 'noreply@' . $_SERVER['HTTP_HOST'];
$bounce = 'x' . 'bounce@' . trim($_SERVER["SERVER_NAME"]) . '.local';
$siteHost = $_SERVER['SERVER_NAME'];
$label = 'Served by ' . $_SERVER['SERVER_NAME'];
$current = $_SERVER['HTTP_HOST'];
function contact()
{
$base = strtolower($_SERVER['HTTP_HOST']);
$base = str_replace('www.', '', $base);
return 'help@' . $base;
}
function fallback()
{
$base = $_SERVER['HTTP_HOST'];
$base = 'example.org';
return 'help@' . $base;
}
class Mailer
{
public function configure()
{
$this->mailDomain = $_SERVER['HTTP_HOST'];
}
public function safe(array $known)
{
if (in_array($_SERVER['HTTP_HOST'], $known, true)) {
$this->replyHost = $_SERVER['HTTP_HOST'];
}
}
}Reported:
- line 2: E-mail address built from client-controlled $_SERVER['HTTP_HOST']; validate it against a whitelist.
- line 3: E-mail address built from client-controlled $_SERVER['SERVER_NAME']; validate it against a whitelist.
- line 4: Client-controlled host name stored here; validate it against a whitelist.
- line 12: E-mail address built from client-controlled $_SERVER['HTTP_HOST']; validate it against a whitelist.
- line 26: Client-controlled host name stored here; validate it against a whitelist.
Configure
In custos.json:
json
{
"rules": {
"HostnameSubstitution": {
"enabled": false
}
}
}Suppress
Before the statement or declaration (or the first statement of the file), either of:
php
// @custos-ignore HostnameSubstitution
/**
* @noinspection HostnameSubstitutionInspection
*/