E-Mail:

PHP Exploit Code in a GIF file?

Can a GIF image file that has been altered to contain PHP exploit code execute? Lorna Hutcheson asks in a post on the SANS Diary:

It is a clever way to pass exploit code to others without it setting off alarms or attracting attention all while bypassing network security tools. Steve reported it to the Web site owners and now a quick check back of the site shows a completely different file with the same name there now. So who switched the image? The person who placed it there to begin with or the folks running the Web site?

The second idea, but completely untested at this point, is that PHP will ignore everything else and just look for its delimiters. Which means it would be a great method for an RFI attack.

Regardless, its interesting and scary to find a file that acts like a regular GIF file, but contains a script exploit. Nice catch Steve, thanks for passing it along!

Could PHP really be reading the code or is it an exploit in GD, ImageMagick, or another graphics manipulation library? This doesn’t make much sense to me.

[PHP Exploit Code in a GIF]

[tags]php, web design[/tags]

What Do You Think?

 

Want to Start a Blog Here for Free?

Are you an expert in one subject or another? If your goal is to help others and dispense your hard-earned information back to the community, get involved in our community site today! You can write about anything - no matter the topic. Exceptional candidates will be offered the chance to contribute to (and generate revenue from) the main Lockergnome site. Join us today!

Canon, Deals & Freebies, Gadgets, Gifts, Hard Drives & Storage, Photography, TVs, TiVo & Home Theater - Nov 26, 2008

Wednesday Morning Deals 11/26

Apple & Mac, Cooking, DVDs & Blu-Ray, Deals & Freebies, Health, Nikon - Nov 14, 2008

Friday Morning Deals 11/14

77 queries / 1.761 seconds.