Re: Dismantling the lies...
| From: | sean finney | Date: | Mon, 21 May 2007 21:46:27 +0000 |
| Subject: | Re: Dismantling the lies... | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 12 13 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-29645@lists.php.net to get a copy of this message | ||
hi guys,
sorry to butt in here, but thought i'd have something to add/ask:
On Mon, 2007-05-21 at 15:49 -0500, Richard Lynch wrote:
>
> If I'm understanding this correctly, (and that's definitely debatable)
> there seems to be an awfully large "hole" there of being able to poke
> random bits of RAM.
<snip>
> So, really, if a Bad Guy has access to poke random values into your
> RAM, is PHP even relevant to this hack?...
i've heard (though not confirmed myself) that if php is running as a
loadable apache module it is possible to use such a local attack
vector to read from the apache parent's memory, and extract tasty
morcels such as unencrypted SSL keys. obviously this would have an
impact on the severity of otherwise mundane local exploits.
is that FUD, or... ?
sean
Attachment: [application/pgp-signature] This is a digitally signed message part signature.asc
Attachment: [application/pgp-signature] This is a digitally signed message part signature.asc