RE: [PHP] Fwd: BadBlue v1.02 beta for Windows 98, ME and 2000 .php Source Code Disclosure Vulnerability
| From: | Tom Malone | Date: | Wed, 22 Aug 2001 16:10:31 +0000 |
| Subject: | RE: [PHP] Fwd: BadBlue v1.02 beta for Windows 98, ME and 2000 .php Source Code Disclosure Vulnerability | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-63926@lists.php.net to get a copy of this message | ||
This is not an issue if you're site is using Apache, correct?
Tom Malone
Web Designer
http://www.tom-malone.com
-----Original Message-----
From: Kurth Bemis [mailto:kurth@usaexpress.net]
Sent: Wednesday, August 22, 2001 11:13 AM
To: php-general@lists.php.net
Subject: [PHP] Fwd: BadBlue v1.02 beta for Windows 98, ME and 2000 .php
Source Code Disclosure Vulnerability
Thought this may be of interest to somebody.
~kurth
>Delivered-To: kurth@usaexpress.net
>Mailing-List: contact vuln-dev-help@securityfocus.com; run by ezmlm
>List-Id: <vuln-dev.list-id.securityfocus.com>
>List-Post: <mailto:vuln-dev@securityfocus.com>
>List-Help: <mailto:vuln-dev-help@securityfocus.com>
>List-Unsubscribe:
><mailto:vuln-dev-unsubscribe@securityfocus.com>
>List-Subscribe:
><mailto:vuln-dev-subscribe@securityfocus.com>
>Delivered-To: mailing list vuln-dev@securityfocus.com
>Delivered-To: moderator for vuln-dev@securityfocus.com
>From: "acz [iSecureLabs]" <aurelien.cabezon@iSecureLabs.com>
>To: <vuln-dev@securityfocus.com>, <nt-securite@ossir.org>
>Cc: <support@badblue.com>
>Subject: BadBlue v1.02 beta for Windows 98, ME and 2000 .php Source Code
>Disclosure Vulnerability
>Date: Wed, 22 Aug 2001 11:11:28 +0200
>X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
>Importance: Normal
>
>-- [ iSecureLabs BadBlue v1.02 beta for Windows 98, ME and 2000
>Advisory ] --
>
>BadBlue v1.02 beta for Windows 98, ME and 2000 .php Source Code Disclosure
>Vulnerability
>Problem discovered: 22/08/2001
>
>-- [ Overview ] --
>
>BadBlue http://badblue.com/ is a tiny, free download that lets
>you share
>files, search other
>PCs and even run powerful web applications.
>Badblue support .php extension.
>It is possible to retrieve full .php source code.
>
>-- [ Description ] --
>
>Badblue contains an input validation vulnerability which may lead to
>download the full source code of .php pages.
>This is due to a lack of checks for NULL bytes.
>
>Exemple:
>http://myBadBlue.com/test.php%00
>
>Note: It is possible too to download .dll file used by BadBlue.
>
>Exmeple:
>http://myBadBlue.com/ext.dll%00
>
>-- [ Tested Version ] --
>
>BadBlue v1.02 beta for Windows 98, ME and 2000
>
>-- [ Discovered by ] --
>
>Cabezon Aurelien | aurelien.cabezon@iSecureLabs.com
>http://www.iSecureLabs.com | French Security portal
>http://www.isecurelabs.com/advisory/badblue.html
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
For additional commands, e-mail: php-general-help@lists.php.net
To contact the list administrators, e-mail: php-list-admin@lists.php.net