Collected research
Anonymizing RFI Attacks Through Google
SecuriTeam Blogs » Anonymizing RFI Attacks Through Google
Noam Rathaus turns Googlebot into an attack proxy: publish a URL that combines a victim's remote-file-inclusion parameter with an attacker-hosted PHP shell, and Google's crawler fetches it, exploiting the third party on the attacker's behalf and leaving the crawler's address in the logs. Shown live via inurl:cmd.gif, and generalisable to any spider or as a covert channel.
Record
- Document
- SecuriTeam Blogs » Anonymizing RFI Attacks Through Google
- Researcher
- Noam Rathaus
- Published by
- blogs.securiteam.com
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Noam Rathaus, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .