Re: Strange Apache log entry

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]



On 08/28/2010 05:30 AM, Stephen Harris wrote:
> In general it's not just PHP; it could be perl, script.. anything
> eg this extremely bad and broken CGI program:

That's true, but /proc/environ isn't in a format that's valid for most 
languages.  If a PHP script can be made to include /proc/environ, code 
can be injected by the caller.  For instance, their Agent string could 
include PHP code which would end up executed.  Other languages may not 
be as prone to that specific issue.
_______________________________________________
CentOS mailing list
CentOS@xxxxxxxxxx
http://lists.centos.org/mailman/listinfo/centos


[Index of Archives]     [CentOS]     [CentOS Announce]     [CentOS Development]     [CentOS ARM Devel]     [CentOS Docs]     [CentOS Virtualization]     [Carrier Grade Linux]     [Linux Media]     [Asterisk]     [DCCP]     [Netdev]     [Xorg]     [Linux USB]
  Powered by Linux