From 22d7df91163ea2e330f02ad3f165e8fd23e3627b Mon Sep 17 00:00:00 2001 From: DL6ER Date: Wed, 3 Feb 2021 14:01:43 +0100 Subject: [PATCH 1/3] Properly escape possible user-input Signed-off-by: DL6ER --- scripts/pi-hole/php/auth.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/scripts/pi-hole/php/auth.php b/scripts/pi-hole/php/auth.php index 7398cbdf..2046261a 100644 --- a/scripts/pi-hole/php/auth.php +++ b/scripts/pi-hole/php/auth.php @@ -83,7 +83,7 @@ function check_cors() { $server_origin = str_replace(array("[","]","http://","https://"), array("","","",""), $server_origin); if(!in_array($server_origin, $AUTHORIZED_HOSTNAMES)) { - log_and_die("Failed CORS: " . $server_origin .' vs '. join(', ', $AUTHORIZED_HOSTNAMES)); + log_and_die("Failed CORS: " . htmlspecialchars($server_origin) .' vs '. join(', ', $AUTHORIZED_HOSTNAMES)); } header("Access-Control-Allow-Origin: ${_SERVER['HTTP_ORIGIN']}"); } From d4e46df28e33968687037631cd29289e351ab89c Mon Sep 17 00:00:00 2001 From: DL6ER Date: Wed, 3 Feb 2021 14:06:32 +0100 Subject: [PATCH 2/3] Prevent javascript XSS attacks aimed to steal the session ID Signed-off-by: DL6ER --- scripts/pi-hole/php/auth.php | 5 +++++ scripts/pi-hole/php/password.php | 6 +++++- 2 files changed, 10 insertions(+), 1 deletion(-) diff --git a/scripts/pi-hole/php/auth.php b/scripts/pi-hole/php/auth.php index 2046261a..21a25c46 100644 --- a/scripts/pi-hole/php/auth.php +++ b/scripts/pi-hole/php/auth.php @@ -97,6 +97,11 @@ function check_csrf($token) { session_id() == ""; if(!$session_started) { + // Start a new PHP session (or continue an existing one) + // Prevents javascript XSS attacks aimed to steal the session ID + ini_set('session.cookie_httponly', 1); + // Prevent Session ID from being passed through URLs + ini_set('session.use_only_cookies', 1); session_start(); } diff --git a/scripts/pi-hole/php/password.php b/scripts/pi-hole/php/password.php index b3da977a..5dd03dd8 100644 --- a/scripts/pi-hole/php/password.php +++ b/scripts/pi-hole/php/password.php @@ -9,6 +9,10 @@ require_once('func.php'); // Start a new PHP session (or continue an existing one) + // Prevents javascript XSS attacks aimed to steal the session ID + ini_set('session.cookie_httponly', 1); + // Prevent Session ID from being passed through URLs + ini_set('session.use_only_cookies', 1); session_start(); // Read setupVars.conf file @@ -39,7 +43,7 @@ // Test if password is set if(strlen($pwhash) > 0) { - // Check for and authorize from persistent cookie + // Check for and authorize from persistent cookie if (isset($_COOKIE["persistentlogin"])) { if (hash_equals($pwhash, $_COOKIE["persistentlogin"])) From 64b36564c5cd9bbe62cf67c5861c3026e9fe826e Mon Sep 17 00:00:00 2001 From: DL6ER Date: Wed, 3 Feb 2021 14:37:58 +0100 Subject: [PATCH 3/3] Regenerate session ID on successful login to prevent session fixation Signed-off-by: DL6ER --- scripts/pi-hole/php/password.php | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/scripts/pi-hole/php/password.php b/scripts/pi-hole/php/password.php index 5dd03dd8..01e7efd6 100644 --- a/scripts/pi-hole/php/password.php +++ b/scripts/pi-hole/php/password.php @@ -65,6 +65,13 @@ $postinput = hash('sha256',hash('sha256',$_POST["pw"])); if(hash_equals($pwhash, $postinput)) { + // Regenerate session ID to prevent session fixation + session_regenerate_id(); + + // Clear the old session + $_SESSION = array(); + + // Set hash in new session $_SESSION["hash"] = $pwhash; // Login successful, redirect the user to the homepage to discard the POST request