Mailing List Archive
tlug.jp Mailing List tlug archive tlug Mailing List Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]Re: [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- Date: Thu, 05 Jun 2008 20:09:02 +0900
- From: dave@example.com
- Subject: Re: [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- References: <78d7dd350806042138r226b625do6f30eb68cc80e732@mail.gmail.com> <b4d277190806042240l1b0d2cadme275cf77dccdd79a@mail.gmail.com> <78d7dd350806042336j65d47ec9n382205fe5f566e13@mail.gmail.com> <b4d277190806050054w49fffad4v1b12acb8a22ad7d0@mail.gmail.com> <78d7dd350806050128l292de4e5he926d9beb7c27024@mail.gmail.com> <b4d277190806050210m250751aav4e5436e89c9e6957@mail.gmail.com>
- User-agent: Gnus/5.11 (Gnus v5.11) Emacs/22.1 (gnu/linux)
"Edmund Edgar" <lists@example.com> writes: > 2008/6/5 Hung Nguyen Vu <vuhung16plus+shape@example.com>: >> If "he" wants to execute "php freebsd.jpg" he need a shell first. > > Correct. Putting it in the jpeg gets the hostile code onto your > server, but the attacker still has to do something so that the PHP > program executes it. > > Change the name of your jpeg file from freebsd.jpg to freebsd.php, then go to: > http://aoclife.ddo.jp/tmp/freebsd.php. > > ...an attacker wouldn't usually be able to upload the file with the > extension .php in the first place. As previously, they'd need to find > another vulnerability somewhere to persuade the PHP program on the > server to run the file. I think tricking a PHP script into include-ing the malicious jpeg would get it to run the embedded code. Including files based on parameters passed in via URL seems to be a pretty common way for PHP apps to get exploited. Dave
- References:
- [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- From: Hung Nguyen Vu
- Re: [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- From: Edmund Edgar
- Re: [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- From: Hung Nguyen Vu
- Re: [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- From: Edmund Edgar
- Re: [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- From: Hung Nguyen Vu
- Re: [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- From: Edmund Edgar
Home | Main Index | Thread Index
- Prev by Date: Re: [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- Next by Date: Re: [tlug] Now, this is getting out of hand!
- Previous by thread: Re: [tlug] Clamav reports a virus: Exploit.Gif.PHPembedded
- Next by thread: [tlug] Keyboard Issues
- Index(es):
Home Page Mailing List Linux and Japan TLUG Members Links