Security researchers have found PHP exploit code embedded in a GIF on a major image-hosting site.

The exploit code slipped through the site's defences with the aid of a legitimate image at the beginning of the file, according to a blog post on the Sans Institute's Internet Storm Center.

"It is a clever way to pass exploit code to others without it setting off alarms or attracting attention all while bypassing network security tools," the SANS security blog noted.

Malicious attackers planted PHP coded exploit script within an image file. PHP is often used as a programming language to create dynamic Web sites.

Once this type of malicious GIF is uploaded to a server, it can create havoc by remotely allowing more exploits to be deployed on the system, said Johannes Ullrich, chief research officer for the SANS Institute.

When users download the image to view it, the server parses the PHP code and the exploit is executed, as it serves the image to the user.

Over the past six months, this type of technique has been cropping up with greater frequency from small family Web sites to, more recently, a major image hosting site, Ullrich said.

Related links

Comments

1

Ads - 24/09/07

How do you filter images such as gif with embedded code in it before uploading it in server?

» Report offensive content

2

Max - 22/10/07

umesh, please Shut up. You're an idiot.

» Report offensive content

3

manikanta - 10/11/07

Leave a comment

You must read and type the 6 chars within 0..9 and A..F

* indicates mandatory fields.

3

manikanta - 11/10/07

policy means ... more

2

Max - 22/10/07

umesh, please Shut up. You're an idiot. ... more

1

Ads - 24/09/07

How do you filter images such as gif with embedded code in it before uploading it in server? ... more

Log in


Sign up | Forgot your password?

  • Staff Aussies to pay more for Win 7

    If you are looking to make some money in these troubled times, perhaps importing copies of Windows 7 could be for you. Read more »

    -- posted by Staff

  • Staff Firefox: Greens want it, 3.5rc2 not up to par

    This week's roundup looks at the situation surrounding a campaign to change Outlook HTML renderer, a Greens MP wants to install Firefox but is restricted and all the photos from the iPhone 3GS launch. Read more »

    -- posted by Staff

  • Chris Duckett Microsoft misses the Outlook point

    Ask designers which mail program is the bane of their existence, and you'll find that Outlook tops the list. The reason why the most popular email reader is also the most painful is simple: it uses Word to render HTML emails. Read more »

    -- posted by Chris Duckett

What's on?