Get a Pentest and security assessment of your IT network.

News

Remote Code Execution in PHP Explained – Part 1

An attacker can give values like Paulos;ls la for windows systems and execute the ls la command. Null byte can be achieved by writing some regular expression with the help of our dear friend, the null byte. In some functions that are used to include the code inside the page, if an untusted file is used to dynamically include files inside a file, it would result in the same vulnerability. There is no function designed in PHP to properly escape eval.”]

Source: http://www.rafayhackingarticles.net/2014/08/remote-code-execution-in-php-explained.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Take note, next week update Adobe Reader and Acrobat to fix critical flaws

News

NSA-linked Cisco exploit poses bigger threat than previously thought