PHWinfo banniere

Titres
PORTAIL ANNUAIRE ARTICLES COMPARATEUR HÉBERGEURS DEVIS FORUMS RÉDUCTEUR D'URL
Précédent   PHWinfo > Autres forums > Forum Programmation & Conception > alt.www.webmaster > New PHP Vulns Reported
S'inscrire FAQ Membres Recherche Messages du jour Marquer les forums comme lus
New PHP Vulns Reported

Réponse
 
LinkBack Outils de la discussion
Vieux 04/01/2008, 18h19   #1
I Hate Stock Spamz
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut New PHP Vulns Reported

Secunia reports several new vulnerabilities for PHP which have <allegedly>
been fixed in the release 4.4.8. (http://secunia.com/advisories/28318/)
Among those are:
Integer overflow error in the "chunk_split()" function
Integer overflow errors in "strcspn()" & "strspn()" frequently used
Regression error in "glob()" function
SQL error as regards "LOCAL INFILE"
"session_save_path" and "error_log" can bypass "safe_mode"

These can all be remotely exploited.
Patch now or pay later!

BTW, they also released yet another advisory about a critical vulnerability
in Real Player. No patch is as yet provided.
(http://secunia.com/advisories/28276/). Careful about where you get your
media files, particularly websites.

  Réponse avec citation
Vieux 04/01/2008, 20h03   #2
Jerry Stuckle
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: New PHP Vulns Reported

I Hate Stock Spamz wrote:
> Secunia reports several new vulnerabilities for PHP which have <allegedly>
> been fixed in the release 4.4.8. (http://secunia.com/advisories/28318/)
> Among those are:
> Integer overflow error in the "chunk_split()" function
> Integer overflow errors in "strcspn()" & "strspn()" frequently used
> Regression error in "glob()" function
> SQL error as regards "LOCAL INFILE"
> "session_save_path" and "error_log" can bypass "safe_mode"
>
> These can all be remotely exploited.
> Patch now or pay later!
>
> BTW, they also released yet another advisory about a critical vulnerability
> in Real Player. No patch is as yet provided.
> (http://secunia.com/advisories/28276/). Careful about where you get your
> media files, particularly websites.
>
>


Considering PHP 4.x is past end of life, that's nothing new.

--
==================
Remove the "x" from my email address
Jerry Stuckle
JDS Computer Training Corp.
jstucklex@attglobal.net
==================

  Réponse avec citation
Vieux 05/01/2008, 13h17   #3
Secret Agent X
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: New PHP Vulns Reported

I Hate Stock Spamz <mister@ellaneous.cn> wrote:

>These can all be remotely exploited.
>Patch now or pay later!


Paranoida aside, please explain:

1) How can these be remotely exploited, and to what ends?

2) How many sites are currently exploited, and what is being done
through those exploits?

(Facts please, I know this is AWW, but if the usual suspects could
spare us the usual bullshit)

X


  Réponse avec citation
Vieux 05/01/2008, 14h48   #4
John Bokma
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: New PHP Vulns Reported

(Secret Agent X) wrote:

> I Hate Stock Spamz <mister@ellaneous.cn> wrote:
>
>>These can all be remotely exploited.
>>Patch now or pay later!

>
> Paranoida aside, please explain:
>
> 1) How can these be remotely exploited, and to what ends?


This are two questions, I'll answer the latter: the ends is often to
install software to send out spam / to scan for other exploitable sites /
to infect computers of visitors.

> 2) How many sites are currently exploited, and what is being done
> through those exploits?


Again two questions, will answer the latter: in some cases nothing until
it's reported, or the site owner notices a huge increase in traffic. The
latter can take weeks, or even months.

--
John Bokma http://johnbokma.com/
  Réponse avec citation
Vieux 06/01/2008, 16h10   #5
Secret Agent X
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: New PHP Vulns Reported

John Bokma <john@castleamber.com> wrote:

>(Secret Agent X) wrote:
>
>> I Hate Stock Spamz <mister@ellaneous.cn> wrote:
>>
>>>These can all be remotely exploited.
>>>Patch now or pay later!

>>
>> Paranoida aside, please explain:
>>
>> 1) How can these be remotely exploited, and to what ends?

>
>This are two questions, I'll answer the latter: the ends is often to
>install software to send out spam / to scan for other exploitable sites /
>to infect computers of visitors.


No answer there then. Just more scaremongering.


>
>> 2) How many sites are currently exploited, and what is being done
>> through those exploits?

>
>Again two questions, will answer the latter: in some cases nothing until
>it's reported, or the site owner notices a huge increase in traffic. The
>latter can take weeks, or even months.


Again just more scaremongering. I assume that "I Hate Stock Spamz" who
posted the original scare story is financially involved in the AV
industry and wants to whip up more business. A bit like Alan Soloman
and John McCarthy used to do, when viruses were first invented.

X


  Réponse avec citation
Vieux 06/01/2008, 16h26   #6
John Bokma
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: New PHP Vulns Reported

(Secret Agent X) wrote:

> No answer there then. Just more scaremongering.


I doubt you have any idea about programming, so your way underqualified to
even weight my answers Mr Probert (I assume).

--
John Bokma http://johnbokma.com/
  Réponse avec citation
Vieux 06/01/2008, 20h55   #7
I Hate Stock Spamz
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: New PHP Vulns Reported

"Secret AgentX" trolled:
> Again just more scaremongering. I assume that "I Hate Stock Spamz" who
> posted the original scare story is financially involved in the AV
> industry and wants to whip up more business. A bit like Alan Soloman


Yep, they're after ya'. Them scaremongers like Securityfocus and Secunia.
You just know that there's a plot in there somewhere to create panic and
steal your parent's hard earned cash.

I'll sure be glad when you kids get back in school next week.

BTW, if you had any ideas about these vulns you could easily find POC
scripts around the net, don't expect any of the grownups in here to
publish them for you.

  Réponse avec citation
Vieux 07/01/2008, 09h19   #8
Secret Agent X
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: New PHP Vulns Reported

I Hate Stock Spamz <mister@ellaneous.cn> wrote:

>"Secret AgentX" trolled:
>> Again just more scaremongering. I assume that "I Hate Stock Spamz" who
>> posted the original scare story is financially involved in the AV
>> industry and wants to whip up more business. A bit like Alan Soloman

>
>Yep, they're after ya'. Them scaremongers like Securityfocus and Secunia.
>You just know that there's a plot in there somewhere to create panic and
>steal your parent's hard earned cash.
>
>I'll sure be glad when you kids get back in school next week.
>
>BTW, if you had any ideas about these vulns you could easily find POC
>scripts around the net, don't expect any of the grownups in here to
>publish them for you.
>


You have no idea who I am, have you? Ever heard of the goat files? I
remember them.

Anyway, as we can see, you have published no evidence to support your
claims, just scaremongering drivel. I suggest people just ignore this
rubbish and apply common sense, unless they like throwing money at the
corporate criminals.

X




  Réponse avec citation
Réponse


Outils de la discussion

Règles de messages
Vous ne pouvez pas créer de nouvelles discussions
Vous ne pouvez pas envoyer des réponses
Vous ne pouvez pas envoyer des pièces jointes
Vous ne pouvez pas modifier vos messages

Les balises BB sont activées : oui
Les smileys sont activés : oui
La balise [IMG] est activée : oui
Le code HTML peut être employé : non
Trackbacks are oui
Pingbacks are oui
Refbacks are oui


Fuseau horaire GMT +1. Il est actuellement 22h42.


Édité par : vBulletin® version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0 RC5 Tous droits réservés.
Version française #16 par l'association vBulletin francophone
PHWinfo est un site Éducation Sans Frontières ©2000-2008
Ad Management by RedTyger
©Tous droits réservés par les parties respectives
Page generated in 0,13581 seconds with 16 queries