| To: | rurban@x-ray.at |
|---|---|
| Subject: | Re: Critical phpwiki c99shell exploit |
| From: | Gadi Evron <ge@linuxbox.org> |
| Date: | Thu, 12 Apr 2007 11:50:19 -0500 (CDT) |
| Cc: | bugtraq@securityfocus.com |
| Delivered-to: | sp-com-lists@consult.net |
| Delivered-to: | bugtraq-list@securepoint.com |
| Delivered-to: | mailing list bugtraq@securityfocus.com |
| Delivered-to: | moderator for bugtraq@securityfocus.com |
| In-reply-to: | <20070412131414.17191.qmail@securityfocus.com> |
| List-help: | <mailto:bugtraq-help@securityfocus.com> |
| List-id: | <bugtraq.list-id.securityfocus.com> |
| List-post: | <mailto:bugtraq@securityfocus.com> |
| List-subscribe: | <mailto:bugtraq-subscribe@securityfocus.com> |
| List-unsubscribe: | <mailto:bugtraq-unsubscribe@securityfocus.com> |
| Mailing-list: | contact bugtraq-help@securityfocus.com; run by ezmlm |
On 12 Apr 2007 rurban@x-ray.at wrote: > Via the Phpwiki 1.3.x UpLoad feature some hackers from russia uploaded a php3 > or php4 file, > install a backdoor at port 8081 and have access to your whole disc and > overtake the server. > > A url in the file is http://ccteam.ru/releases/c99shell > > The uploaded file has a php, php3 or php4 extension and looks like a gif to > the mime magic. > So apache usually accepts it. > > To fix this phpwiki issue at first move the lib/plugin/UpLoad.php file out of > this directory. > > You can fix it by adding those two lines to your list of disallowed > extensions: > php3 > php4 > Currently only "php" is disallowed. > This is a good best practice, but it doesn't hold water long range. Further, where do you disallow these extensions? In the application? Mostly what the bad guys would do is upload, say.. .jpg, and then rename it. Gadi. |
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [security bulletin] HPSBGN02199 SSRT071312 rev.1 - Mercury Quality Center ActiveX, Remote Unauthorized Arbitrary Code Execution, security-alert |
|---|---|
| Next by Date: | Re: Critical phpwiki c99shell exploit, Jamie Riden |
| Previous by Thread: | Critical phpwiki c99shell exploit, rurban |
| Next by Thread: | RE: Critical phpwiki c99shell exploit, Ryan Neufeld |
| Indexes: | [Date] [Thread] [Top] [All Lists] |