Current location: Hot Scripts Forums » Programming Languages » PHP » MAJOR php security threat.


MAJOR php security threat.

Reply
  #1 (permalink)  
Old 12-17-04, 06:42 PM
nickvd nickvd is offline
New Member
 
Join Date: Dec 2004
Posts: 3
Thanks: 0
Thanked 0 Times in 0 Posts
Exclamation MAJOR php security threat.

ALL PHP SERVERS MUST BE UPGRADED A.S.A.P...

The following is quoted from this security advisory i just saw on slashdot...

Url to /. story: http://developers.slashdot.org/devel...id=169&tid=172

Url to advisory: http://www.hardened-php.net/advisories/012004.txt

This is not something to be taken lightly... This very forum is susceptible to the attacks that are currently happening throuout the globe. If you run php, with a version less than 4.3.10 or 5.0.3 you ARE VULNERABLE...

Quote:
...clipped...

Additionally to bug 06 the previous version of the variable
unserializer allowed setting references to already freed entries in
the variable hash. A skilled attacker can exploit this to create
an universal string that will pass execution to an arbitrary
memory address when it is passed to unserialize(). For AMD64 systems
it was even possible to developed a string that directly passes
execution to shellcode contained in the string itself.

It is necessary to understand that these strings can exploit a
bunch of popular PHP applications remotely because they pass f.e.
cookie content to unserialize().

Examples of vulnerable scripts:

- phpBB2
- Invision Board
- vBulletin
- Woltlab Burning Board 2.x
- Serendipity Weblog
- phpAds(New)
- ...

Last edited by Nico; 04-28-09 at 04:48 AM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiShare on FacebookShare on Stumble UponShare on Twitter
Reply With Quote
Reply

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
A new way to test your site's security Eclipse PHP 2 09-25-04 10:46 AM
security concerns new purchased script Ron_Long_Beach PHP 3 09-23-04 02:45 AM
Let's talk security Mister B. PHP 1 09-11-04 06:15 PM
Security for my Website? Naresh Rohra ASP 1 08-27-04 03:07 PM
How to supress security prompt in Mozilla browser rameshreddy74 JavaScript 0 01-14-04 12:53 AM


All times are GMT -5. The time now is 06:36 AM.
vBulletin® Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.