“php shell script on my server”
January 24th, 2008 by Administrator, Filed under: Ask the Expert
Q:
I have a webserver where i’ve found several different php shell scripts and I’d like to know how they got there. Are there known vulnerabilities that allow uploading of php files to a server?
I have several sites running on this server with several php script packages including…
Zencart
phpbb2
Any ideas or pointers will be appreciated!
A: Hi,
There are several vulnerabilities in both off the shelf products as well as custom PHP scripts that would allow “uploading”, in essence they don’t need to upload, they just need to get your PHP scripts to execute an arbitrary (outside) PHP script.
PHPbb has several:
http://www.securiteam.com/cgi-bin/htsearch?sort=score&words=phpbb
Listed as Code Execution, Arbitrary File Upload, etc.
While zencart has just one problem:
http://www.securiteam.com/cgi-bin/htsearch?sort=score&words=zen+cart
But that could be misleading, and just mean that the software is very uncommon.
-
Woody Mon
-
http://www.kuroiwebdesign.com Kuroi
-
Kfir
-
Joseph Pierini
-
A Happy Zen Cart User
-
Kfir
-
http://www.webdigi.co.uk Jason
-
http://www.filmizlermisin.com film izle
-
http://www.webgazeteler.com gazeteler
-
http://www.hikaye.biz hikaye
-
http://www.teamads.com HTML Static Websites
-
http://www.rightwaysolution.com PHP web development
-
http://www.esux.net Zizzi
-
http://www.karakocannostalji.com karakocan
-
http://www.mynike-shoes.com/Nike-Shox-R4.html wholesale Shox R4 Zoom shoes
-
http://rdllplayer.microbloghost.com/ Chinese boy
-
http://www.cher4life.com transfer factor
-
http://www.obdsvs.com/ launch x431,lexia3,mb star



