Dailydave mailing list archives

On "Application Level Rootkits"


From: LMH <lmh () info-pull com>
Date: Wed, 31 Jan 2007 22:24:30 +0100

I'm curious if someone else has ever done work around a PHP extension
backdoor. I've been checking code around and it seems to be a nice
possibility.

Drop the extension and have the target host send a blue haired Goatse
image when a specific token is passed via the query string to any PHP
script. Or something else more fruitful.

-- Lance.
_______________________________________________
Dailydave mailing list
Dailydave () lists immunitysec com
http://lists.immunitysec.com/mailman/listinfo/dailydave


Current thread: