note 54886 deleted from ref.info by mazzanet
| From: | mazzanet@php.net | Date: | Tue, 19 Jul 2005 07:35:01 +0000 |
| Subject: | note 54886 deleted from ref.info by mazzanet | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-92144@lists.php.net to get a copy of this message | ||
Note Submitter: james at gogo dot co dot nz
----
WARNING: enable_dl/dl()
*********************
There is an exploit circulating currently which takes advantage of dl() to inject code into Apache
which causes all requests to all virtual hosts to be redirected to a page of the attackers choice.
All operators of shared web hosting servers with Apache and PHP should disable dl() by setting
enable_dl to off otherwise your servers are vulnerable to this exploit.
This exploit is generally known as flame.so (the object that is loaded into Apache) and flame.php
(the php script that loads it).
Google gives more information:
http://www.google.co.nz/search?q=flame.so+flame.php