Re: Critical phpwiki c99shell exploit



On 12 Apr 2007 rurban@xxxxxxxx wrote:
Via the Phpwiki 1.3.x UpLoad feature some hackers from russia uploaded a php3 or php4 file,
install a backdoor at port 8081 and have access to your whole disc and overtake the server.

A url in the file is http://ccteam.ru/releases/c99shell

The uploaded file has a php, php3 or php4 extension and looks like a gif to the mime magic.
So apache usually accepts it.

To fix this phpwiki issue at first move the lib/plugin/UpLoad.php file out of this directory.

You can fix it by adding those two lines to your list of disallowed extensions:
php3
php4
Currently only "php" is disallowed.


This is a good best practice, but it doesn't hold water long
range. Further, where do you disallow these extensions? In the
application?

Mostly what the bad guys would do is upload, say.. .jpg, and then rename
it.

Gadi.



Relevant Pages

  • Re: Worst extension ever?
    ... >do, why it isn't working, and how to fix it. ... >cursing the existance of some extensions. ... Engineering Calculations ... the KDP-2 Optical Design Program ...
    (comp.lang.fortran)
  • Re: FP will publish files under 1 MB only
    ... > web servers back on Netscape 4.6, so I am not using them. ... > extensions sounds exactly what I am experiencing, ... I wish they would provide a fix for the ... having the FrontPage server extensions on the server..... ...
    (microsoft.public.frontpage.client)
  • Re: FP XP and Guest Book Problem
    ... fix it. ... > FP extensions are installed. ... >> spam. ...
    (microsoft.public.frontpage.client)
  • Re: Worst extension ever?
    ... Jim Klein wrote: ... That philosophy works up to a point. ... do, why it isn't working, and how to fix it. ... cursing the existance of some extensions. ...
    (comp.lang.fortran)