Webmaster Forum  

Go Back   Webmaster Forum > Web Hosting Forum - Web Hosting - Web Host - Hosting - Managed Hosting - Shared Hosting > Site & Server Administration
User Name
Password
Register FAQ Members List Calendar Transactions Store Search Today's Posts Mark Forums Read


PHP embedded in GIF files

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 01-08-2008, 19:24
sunken
Senior Member

sunken's Avatar

Join Date: Dec 2004
Posts: 242
Trader Rating: (0)
Points: 0 (Donate)
5 F$/Referral Refer Friends
sunken is on a distinguished road
Default PHP embedded in GIF files

There is a security flaw in GIF files that allows a PHP program to be inserted into the GIF file. The way this works is the file has the proper GIF89 headers to make it a valid file (thus not caught by a PHP upload script), but yet the PHP code is embedded. A hacker can use it to find out passwords, etc, since the .php code would run as the webhost.

I never knew this was possible until I read about it when someone tried it on our server.

This site has what you can do about it...
http://www.phpclasses.org/blog/post...GIF-images.html
sunken is offline
Reply With Quote
  #2  
Old 01-09-2008, 12:20
agilius
Member


Join Date: Jan 2008
Posts: 43
Trader Rating: (0)
Points: 29 (Donate)
5 F$/Referral Refer Friends
agilius is on a distinguished road
Default

I saw many times that when I loaded a page (page.php) I was redirected to a 1px gif page. What that the "hackers" pages? If so, how could I protect myself from this kind of hack?
agilius is offline
Reply With Quote
  #3  
Old 01-09-2008, 19:10
sunken
Senior Member

sunken's Avatar

Join Date: Dec 2004
Posts: 242
Trader Rating: (0)
Points: 0 (Donate)
5 F$/Referral Refer Friends
sunken is on a distinguished road
Default

It's hard to say from your description what their intent was. It could be anything from a cookie reader, a wrong redirect, a page tracker, or a legitimate purpose. Not sure what you could do to avoid those, except to only go to trusted sites, which I know is not the most practical of advice in the real world.
sunken is offline
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
What is PHP, Here i will tell you what is PHP booster20002005 Programming 1 08-20-2007 04:04
80 cheap Script for sale teampower Content 0 06-29-2007 02:08
Free Host-Domain-Pop3Mails ceberus Free Web Hosting Discussions And Reviews 1 06-15-2007 07:10
PHP Designer 2005 Positive Other Free Resources 1 08-30-2005 01:13
How To : Improve Your PHP Programming admans Website Design Forum 0 07-17-2005 07:58

Resources : | Advertise at FHF | itextLink.com| Reseller Hosting| TextDot| iNamePros| Any Webmaster| Web Host| Dep3| cheap low cost web hosting reviews|


All times are GMT -4. The time now is 02:17.


Powered by: vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.