Mailing List Archive
tlug.jp Mailing List tlug archive tlug Mailing List Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]Re: [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- Date: Thu, 5 Jun 2008 18:47:57 +0900
- From: "Hung Nguyen Vu" <vuhung16plus+shape@example.com>
- Subject: Re: [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- References: <78d7dd350806042138r226b625do6f30eb68cc80e732@mail.gmail.com> <b4d277190806042240l1b0d2cadme275cf77dccdd79a@mail.gmail.com> <78d7dd350806042336j65d47ec9n382205fe5f566e13@mail.gmail.com> <b4d277190806050054w49fffad4v1b12acb8a22ad7d0@mail.gmail.com> <78d7dd350806050128l292de4e5he926d9beb7c27024@mail.gmail.com> <b4d277190806050210m250751aav4e5436e89c9e6957@mail.gmail.com>
On Thu, Jun 5, 2008 at 6:10 PM, Edmund Edgar <lists@example.com> wrote: > Change the name of your jpeg file from freebsd.jpg to freebsd.php, then go to: > http://aoclife.ddo.jp/tmp/freebsd.php. Oh Shit, he did it. But unfortunately, I couldn't rename it to .php. > Of course, if the web application used to upload the jpeg is checking > for what it should be (a .php extension) an attacker wouldn't usually > be able to upload the file with the extension .php in the first place. > As previously, they'd need to find another vulnerability somewhere to > persuade the PHP program on the server to run the file. The same approaches can be applied to PNG, GIF, JPEG, TIFF because those formats allow comments. And combining with some kind of encryption, they can hide the malicious code. What is the name of exploits like this? MIME type? ask you mentioned in the second email? -- Best Regards, Nguyen Hung Vu ( Nguyễn Vũ Hưng ) vuhung16plus{remove}@example.com , YIM: vuhung16 Japan through an eye of a gaijin: http://www.flickr.com/photos/vuhung/tags/fav/
- Follow-Ups:
- Re: [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- From: Stephen J. Turnbull
- References:
- [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- From: Hung Nguyen Vu
- Re: [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- From: Edmund Edgar
- Re: [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- From: Hung Nguyen Vu
- Re: [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- From: Edmund Edgar
- Re: [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- From: Hung Nguyen Vu
- Re: [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- From: Edmund Edgar
Home | Main Index | Thread Index
- Prev by Date: Re: [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- Next by Date: Re: [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- Previous by thread: Re: [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- Next by thread: Re: [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- Index(es):
Home Page Mailing List Linux and Japan TLUG Members Links