Home

Jan 3, 2017

“Unserialize” Function in PHP 7 Allows Attackers to Take Full Control Over Server


PHP 7’s “unserialize” function is plagued by a series of vulnerabilities that could allow an attacker to take full control over affected servers, Check Point security researchers reveal.

 

Category:IT 

PHP 7’s “unserialize” function is plagued by a series of vulnerabilities that could allow an attacker to take full control over affected servers, Check Point security researchers reveal.

Tracked as CVE-2016-7479, CVE-2016-7480, and CVE-2016-7478, the vulnerabilities are new, but they can be exploited in a similar manner as detailed in a separate vulnerability detailed in August. The flaw, a use-after-free in SPL, could be exploited “by using re-usable exploit primitives for PHP 7 unserialize vulnerabilities,” Check Point said in August.

In a report (PDF) that provides full details of the exploitation method, Check Point experts explained that the unserialize function could be abused to read memory, to forge objects, and to achieve code execution on the affected server. They also underlined that the function was dangerous and that it had been proven so numerous times over the past years, although it remained in use.

In August, the security researchers also said that the aforementioned re-usable exploit primitives were general enough to be applied to all vulnerabilities found in the unserialize mechanism. Now, they claim that the newly discovered flaws can be abused in a similar manner, which apparently confirms the previous statement.

What’s more, the security firm notes that flaws in the unserialize mechanism were heavily exploited in PHP 5 by hackers looking to compromise popular platforms, including Magento, vBulletin, Drupal, and Joomla!. Attackers were able to compromise other web servers as well, by sending maliciously crafted data in client cookies.

According to Check Point, the first two of the fresh bugs allow an attacker to take full control over the impacted servers. Thus, they could do “anything they want with the website, from spreading malware to defacing it or stealing customer data,” the security researchers warn.

As for the third bug, it can be abused to generate a Denial of Service (DoS) attack through which the attacker would basically hang the website, move to exhaust its memory consumption, and then shut it down.

The three security issues were made public this week, but they were found earlier this year. According to Check Point, the vulnerabilities were reported to the PHP security team on September 15 and August 6. Two of the vulnerabilities were resolved on October 13 and December 1, but one of them remains unpatched.
“ PHP 7, the latest release of the popular web programming language that powers more than 80% of websites, offers great advantages for website owners and developers. Some of them include doubling the performance and adding numerous functionalities. Yet for hackers, it represents a completely fresh attack vector, where they can find previously undisclosed vulnerabilities,” Check Point notes.

 

authorarticle: Master3395

image: 

keywords: PhP 7, Security issues with PHP, Unserialize in PHP

Previous Article
Next Article

Sponsored Ads:

Discord

Page 1 of 540  >  >>

REVEALED: iPhone 12 batteries leaked

apple.webp

Jul 14, 2020 | Category: Apple | Comments

But can this not be true?

Apple has done it before, ie launched new models with less mAh.

read more…

Top web browsers 2020: Chrome becomes third browser ever with more than 70%

internet.jpg

Jul 13, 2020 | Category: IT | Comments

Google's Chrome in June joined the ranks of Netscape Navigator and Microsoft's Internet Explorer, both of which once dominated the browser landscape.

read more…

What's in the latest firefox 78 starts ESR ESR transition for enterprises

p1200660-100708728-large.jpg

Jul 12, 2020 | Category: IT | Comments

The latest version of Mozilla's browser fixes 13 flaws and starts the annual process of retiring 2019's Extended Support Release and offering customers the latest enterprise-designed build.

read more…

Page 1 of 540  >  >>