The Cache: Technology Expert's Forum
 
*
Welcome, Guest. Please login or register. December 05, 2008, 10:24:01 AM

Login with username, password and session length


Pages: [1]
  Print  
Author Topic: -----------!!Perk!!------------And anyone else running APC should read this  (Read 189 times)
vsloathe
vim ftw!
Global Moderator
Lifer
*****
Online Online

Posts: 636



View Profile
« on: July 25, 2008, 07:40:35 AM »

http://papasian.org/~dannyp/apcsmash.php.txt

Interesting PoC. Patch up!
Logged

perkiset
Olde World Hacker
Administrator
Lifer
*****
Online Online

Posts: 5230


:sniffle: Humor was so much easier before.


View Profile
« Reply #1 on: July 25, 2008, 08:47:16 AM »

I'm not sure I understand all of it VS, a couple QQs if you have a moment:

Quote
being ran by the webserver via mod_php
... is this the standard, non-CGI way of doing things? So compiling from source and installing against APSX is what makes an install mod_php?

Quote
The easiest way to figure out the return address in
 * is to attach gdb to one of the apache children, break it on the exploited function
 * in apc.c, and find the address of fileinfo->fullpath and then add a bit to it so you
 * land in the NOOP padding.
Doesn't someone already need to have access to the box to be here? Is he directing this towards someone doing shared hosting and breaking the machine that they're on?

Quote
you're probably not working on
Well, if you can't do that you're probably not working on a machine that you have permission to be doing this sort of thing against
... further data against last QQ

Quote
This vulnerability opens people up to real attack in any case where include() and friends are called with user input.
.... sooooo... clearly your code should not include other code based on some form of input... in my case particularly, this would be an automatic. Bad plan, that.

Thanks much man - interesting read. I'm gonna check all my versions and see where I'm sitting in any case.

/p
Logged

If I can't be Mr. Root then I don't want to play.
vsloathe
vim ftw!
Global Moderator
Lifer
*****
Online Online

Posts: 636



View Profile
« Reply #2 on: July 25, 2008, 09:36:06 AM »

Just thought it was an interesting PoC. I don't know the answer to all your questions, but reading the forum thread where it came from, it seems as though a remote attacker could cause a buffer overflow in this way if he knew you were running APC and found an unprotected form input.
Logged

Pages: [1]
  Print  
 
Jump to:  

Perkiset's Place Home   Best of The Cache   phpMyIDE: MySQL Stored Procedures, Functions & Triggers
Politics @ Perkiset's   Pinkhat's Perspective   
cache
mart
coder
programmers
ajax
php
javascript
Powered by MySQL Powered by PHP Powered by SMF 1.1.2 | SMF © 2006-2007, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks


Valid XHTML 1.0! Valid CSS!