|
|||||||||||
|
PHP <=5.2.4 open_basedir bypass & code exec & denial of service
From: <laurent.gaffie(at)gmail.com>
Date: Sun Sep 09 2007 - 22:36:21 EDT
"PHP is a widely-used general-purpose scripting language that is especially suited for Web development and can be embedded into HTML." 2) Bug open_basedir bypass & code exec & denial of service http://ca.php.net/manual/fr/function.dl.php 3)Proof of concept /* debian:~# php -v PHP 5.2.4 (cli) (built: Aug 31 2007 16:39:15) Copyright (c) 1997-2007 The PHP Group Zend Engine v2.2.0, Copyright (c) 1998-2007 Zend Technologies */
Proof of concept example :
<?php
ya right ... /etc/passwd dont have any ELF header .
but we agree that it's not checked in anyway by open_basedir.
fine then bypassed .
denial of service :
4)Greets Ivanlef0u,Deimos,Benji,Berga,Soh,and everyones from worldnet: #futurezone & #nibbles 5)Credits
laurent gaffié
This archive was generated by hypermail 2.1.8 : Sun Oct 28 2007 - 06:15:04 EDT |
||||||||||
|
|||||||||||