The problem affects mainly Drupal 8, but the mitigation is recommended anyway -- see https://httpoxy.org

CommentFileSizeAuthor
#2 0001-Mitigate-httpoxy.patch3.92 KBmemtkmcc
Support from Acquia helps fund testing for Drupal Acquia logo

Comments

memtkmcc created an issue. See original summary.

memtkmcc’s picture

Status: Active » Needs review
FileSize
3.92 KB

Patch for nginx attached for review.

memtkmcc’s picture

Title: Mitigate httpoxy » Nginx: mitigate httpoxy
helmo’s picture

About apache ...

Adding 'RequestHeader unset Proxy early' to the Apache/server.tpl.php is easy. But it does depend on mod_headers which we don't enable by default.
The Debian package could be made to handle this, but the regular upgrade script does not use root privileges... and so cannot.

colan’s picture

Title: Nginx: mitigate httpoxy » Block httpoxy attacks

We can deal with both servers in this issue, but keeping the patches separate is fine with me. I'm about to review the Nginx patch above.

  • colan committed 5133c92 on 7.x-3.x authored by memtkmcc
    Issue #2768725 by memtkmcc, colan: Started blocking httpoxy attacks.
    
colan’s picture

That patch looked good; I just added some comment lines. Now onto Apache fixes... I won't be looking into this myself as I'm only running Nginx at the moment.

I also fixed the following:
* Drupal recipe on the Nginx wiki
* Nginx support in Aegir HTTPS (new home of HTTPS support)

colan’s picture

Status: Needs review » Active

Setting back to active for Apache.

helmo’s picture

Status: Active » Fixed

I don't think we have to do anything (as Aegir) for Apache in this case ... They have updated packages available which cover this issue.

Debian 2.4.10-10+deb8u5 and for Ubuntu 2.4.18-2ubuntu3.1

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.