Mailing List Archive
tlug.jp Mailing List tlug archive tlug Mailing List Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]Re: [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- Date: Thu, 5 Jun 2008 18:10:38 +0900
- From: "Edmund Edgar" <lists@example.com>
- Subject: Re: [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- References: <78d7dd350806042138r226b625do6f30eb68cc80e732@mail.gmail.com> <b4d277190806042240l1b0d2cadme275cf77dccdd79a@mail.gmail.com> <78d7dd350806042336j65d47ec9n382205fe5f566e13@mail.gmail.com> <b4d277190806050054w49fffad4v1b12acb8a22ad7d0@mail.gmail.com> <78d7dd350806050128l292de4e5he926d9beb7c27024@mail.gmail.com>
2008/6/5 Hung Nguyen Vu <vuhung16plus+shape@example.com>: > If "he" wants to execute "php freebsd.jpg" he need a shell first. > In the first place, "he" has nothing more than uploading files( jpeg files ) > to my web server. So I assume that he didn't harm my server. Correct. Putting it in the jpeg gets the hostile code onto your server, but the attacker still has to do something so that the PHP program executes it. > This is freebsd.jpg when loaded with a browser ( Apache 2.0.x, PHP 5.2 ): > http://aoclife.ddo.jp/tmp/freebsd.jpg > The FreeBSE deamon is there, and I don't see any binary junk. > > Can you give me a POC? Change the name of your jpeg file from freebsd.jpg to freebsd.php, then go to: http://aoclife.ddo.jp/tmp/freebsd.php. Of course, if the web application used to upload the jpeg is checking for what it should be (a .php extension) an attacker wouldn't usually be able to upload the file with the extension .php in the first place. As previously, they'd need to find another vulnerability somewhere to persuade the PHP program on the server to run the file. Edmund
- Follow-Ups:
- Re: [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- From: Hung Nguyen Vu
- Re: [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- From: dave
- References:
- [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- From: Hung Nguyen Vu
- Re: [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- From: Edmund Edgar
- Re: [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- From: Hung Nguyen Vu
- Re: [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- From: Edmund Edgar
- Re: [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- From: Hung Nguyen Vu
Home | Main Index | Thread Index
- Prev by Date: Re: [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- Next by Date: Re: [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- Previous by thread: Re: [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- Next by thread: Re: [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- Index(es):
Home Page Mailing List Linux and Japan TLUG Members Links