Mailing List Archive
tlug.jp Mailing List tlug archive tlug Mailing List Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]Re: [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- Date: Thu, 5 Jun 2008 17:28:46 +0900
- From: "Hung Nguyen Vu" <vuhung16plus+shape@example.com>
- Subject: Re: [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- References: <78d7dd350806042138r226b625do6f30eb68cc80e732@mail.gmail.com> <b4d277190806042240l1b0d2cadme275cf77dccdd79a@mail.gmail.com> <78d7dd350806042336j65d47ec9n382205fe5f566e13@mail.gmail.com> <b4d277190806050054w49fffad4v1b12acb8a22ad7d0@mail.gmail.com>
On Thu, Jun 5, 2008 at 4:54 PM, Edmund Edgar <lists@example.com> wrote: > I'm talking about what happens if the jpeg file with the PHP content > in it gets run by the PHP interpreter. Oh, it does: php freebsd.jpg really "executes" the code in the command. Please read on. > Likewise, if you put the file up on a website with PHP enabled and > loaded it in a web browser, you'd get some binary junk, followed by a > directory listing, followed by some more binary junk. I don't get you. If "he" wants to execute "php freebsd.jpg" he need a shell first. In the first place, "he" has nothing more than uploading files( jpeg files ) to my web server. So I assume that he didn't harm my server. This is freebsd.jpg when loaded with a browser ( Apache 2.0.x, PHP 5.2 ): http://aoclife.ddo.jp/tmp/freebsd.jpg The FreeBSE deamon is there, and I don't see any binary junk. Can you give me a POC? -- Best Regards, Nguyen Hung Vu ( Nguyễn Vũ Hưng ) vuhung16plus{remove}@example.com , YIM: vuhung16 Japan through an eye of a gaijin: http://www.flickr.com/photos/vuhung/tags/fav/
- Follow-Ups:
- Re: [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- From: Edmund Edgar
- References:
- [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- From: Hung Nguyen Vu
- Re: [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- From: Edmund Edgar
- Re: [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- From: Hung Nguyen Vu
- Re: [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- From: Edmund Edgar
Home | Main Index | Thread Index
- Prev by Date: Re: [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- Next by Date: Re: [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- Previous by thread: Re: [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- Next by thread: Re: [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- Index(es):
Home Page Mailing List Linux and Japan TLUG Members Links