Web Hack List

Collected research

Scanning internal Lan with PHP remote file opening.

Wisec - The WIse SECurity

Stefano Di Paola turns a non-inclusion PHP wrapper sink such as getimagesize($_GET['image']) into an internal network scanner. Open and closed ports are told apart by the wording of the failed-to-open-stream warning, or by response timing when errors are suppressed, over http:// or ftp://. Enables drive-by pharming, router brute force and full LAN scans, with HTTP Basic auth supported.

Record

Document
Wisec - The WIse SECurity
Researcher
Stefano Di Paola
Published by
wisec.it
Topic
Server

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Stefano Di Paola, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .