Apache File Name Parsing Vulnerability

Source: Internet
Author: User

Test environment: apache 2.0.53 winxp, apache 2.0.52 redhat linux 1. the foreign (ssr team) has released multiple advisory vulnerabilities called Apache's MIME module (mod_mime)related loopholes, and the vulnerability attack.php.rar will be executed as a PHP file, including Discuz! The p11.php.php.php.php.php.php.php.php.php.php.php.rar vulnerability. 2. The superhei of S4T published a small feature of apache on the blog, that is, apache checks the Suffix from the end and executes it according to the last valid suffix. In fact, you only need to take a look at the default index. XX files of apache htdocs. 3. superhei has already made it very clear and can make full use of the Upload Vulnerability. I tested it according to the format of files that are generally allowed to be uploaded, and listed the following (unclassified) typical types: rar Backup Type: bak, lock streaming media type: wma, wmv, asx, as, mp4, rmvb Microsoft type: SQL, chm, hlp, shtml, asp Arbitrary type: test, fake, ph4nt0m special type: torrent www.2cto.com program type: jsp, c, cpp, pl, cgi 4. the key to the entire vulnerability is what the apache "Legal suffix" is and can be exploited if it is not "Legal suffix. 5. test environment a. php <? Phpinfo ();?> Then add any suffix for testing, a. php. aaa, a. php. aab ....

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.