{"id":11020,"date":"2019-10-29T09:38:06","date_gmt":"2019-10-29T13:38:06","guid":{"rendered":"https:\/\/blog.litespeedtech.com\/?p=11020"},"modified":"2019-10-29T09:38:06","modified_gmt":"2019-10-29T13:38:06","slug":"litespeed-immune-to-php-exploit-cve-2019-11043","status":"publish","type":"post","link":"https:\/\/lswp.store\/index.php\/2019\/10\/29\/litespeed-immune-to-php-exploit-cve-2019-11043\/","title":{"rendered":"LiteSpeed Immune to PHP Exploit"},"content":{"rendered":"<p><img fetchpriority=\"high\" decoding=\"async\" src=\"https:\/\/lswp.store\/wp-content\/uploads\/2019\/10\/Secure-PHP.jpg\" alt=\"LiteSpeed Immune to PHP Exploit CVE-2019-11043\" width=\"1000\" height=\"500\" class=\"aligncenter size-full wp-image-11024\" srcset=\"https:\/\/lswp.store\/wp-content\/uploads\/2019\/10\/Secure-PHP.jpg 1000w, https:\/\/lswp.store\/wp-content\/uploads\/2019\/10\/Secure-PHP-300x150.jpg 300w, https:\/\/lswp.store\/wp-content\/uploads\/2019\/10\/Secure-PHP-768x384.jpg 768w, https:\/\/lswp.store\/wp-content\/uploads\/2019\/10\/Secure-PHP-600x300.jpg 600w\" sizes=\"(max-width: 1000px) 100vw, 1000px\" \/><\/p>\n<p>The National Vulnerability Database recently published notice of <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2019-11043\">PHP exploit CVE-2019-11043<\/a>.<\/p>\n<p>This exploit allowed remote code execution, particularly in PHP-FPM, the FastCGI Process Manager. One could trigger it by crafting a special request that took advantage of an underflow flaw in the PHP-FPM code.<\/p>\n<p>On October 24th <a href=\"http:\/\/php.net\/\">php.net<\/a> issued three releases (7.1.33, 7.2.24 as well as 7.3.11), all fixing this vulnerability. <\/p>\n<p><strong>While the vulnerability itself was found within PHP, the exploit would usually be triggered in combination with the web server nginx. LiteSpeed Web Server is immune to the PHP exploit.<\/strong><\/p>\n<p>There are two main reasons why LiteSpeed is not vulnerable:<\/p>\n<ol>\n<li>Most importantly, we don&#8217;t use PHP-FPM. We always use <a href=\"https:\/\/www.litespeedtech.com\/open-source\/litespeed-sapi\/php\">our own LiteSpeed SAPI<\/a>.<\/li>\n<li>Whenever we hit the PHP handler, LiteSpeed Web Server verifies that the specified file exists.<\/li>\n<\/ol>\n<p>You can test the exploit via<a href=\"https:\/\/github.com\/neex\/phuip-fpizdam\"> the Go Proof of Concept found here<\/a>. This PoC executes a series of GET requests towards your web server with longer and longer query strings.  On a LiteSpeed Server the output will look something like this:<\/p>\n<pre>\n.\/phuip-fpizdam<a href=\"https:\/\/example.com\/script.php\"> https:\/\/example.com\/script.php\n2019\/10\/28 16:40:39 Base status code is 200\n2019\/10\/28 16:40:41 Detect() returned error: no qsl candidates found, invulnerable or something wrong\n<\/pre>\n","protected":false},"excerpt":{"rendered":"<p>LiteSpeed products are immune to the recently announced PHP Exploit CVE-2019-11043.<\/p>\n","protected":false},"author":1,"featured_media":11024,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[23],"tags":[220],"class_list":["post-11020","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-php"],"jetpack_featured_media_url":"https:\/\/lswp.store\/wp-content\/uploads\/2019\/10\/Secure-PHP.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/posts\/11020","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/comments?post=11020"}],"version-history":[{"count":0,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/posts\/11020\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/media\/11024"}],"wp:attachment":[{"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/media?parent=11020"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/categories?post=11020"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/tags?post=11020"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}