BugTraq
Critical phpwiki c99shell exploit Apr 12 2007 01:14PM
rurban x-ray at (2 replies)
Re: Critical phpwiki c99shell exploit Apr 12 2007 04:59PM
Jamie Riden (jamie riden gmail com)
Re: Critical phpwiki c99shell exploit Apr 12 2007 04:50PM
Gadi Evron (ge linuxbox org) (2 replies)
Re: Critical phpwiki c99shell exploit Apr 16 2007 10:29AM
Taneli Leppä (taneli crasman fi)
Hello,

Gadi Evron wrote:
> This is a good best practice, but it doesn't hold water long
> range. Further, where do you disallow these extensions? In the
> application?
> Mostly what the bad guys would do is upload, say.. .jpg, and then rename
> it.

This is what I do in Apache to directories used to store user
uploaded files:

<Directory "/var/www/html/application/uploaded">
php_admin_flag engine off
</Directory>

--
Taneli Leppä | Crasman Co Ltd
<taneli (at) crasman (dot) fi [email concealed]> | <http://www.crasman.fi/>

[ reply ]
RE: Critical phpwiki c99shell exploit Apr 12 2007 07:50PM
Ryan Neufeld (it magpowersystems com)


 

Privacy Statement
Copyright 2010, SecurityFocus