GeekAmongUs

  • Home
  • About
  • Blog
  • Contact

PHP-CGI Exploit is in the wild. Get protected ASAP.

Posted by willc on May 8, 2012
Posted in: CPanel, News, Practical Security, RedHat, Security.

The vulnerability that sat undetected for 7 years was disclosed last week, but today it has been announced that exploits have been seen in the wild.  They are working on releasing a new patch. This is pretty bad as it’s not exploiting one particular web application, rather, it is exploiting web servers running PHP in general.

The quick fix is to add this to the .htaccess file on your website(s):

RewriteEngine on
RewriteCond %{QUERY_STRING} ^[^=]*$
RewriteCond %{QUERY_STRING} %2d|\- [NC]
RewriteRule .? – [F,L]

Unless you have compiled PHP from source on your web server, you will need to wait for your vendor (Cpanel, WHM, RedHat, CentOS, etc) to release the updated version. I suggest you implement the above .htaccess fix in the meantime.

 

Edit 5/9/12 12:19PM Eastern:

Most cPanel configurations are protected by default: http://www.cpanel.net/2012/05/cpanel-protects-against-php-vulnerability.html

Share this:

  • Twitter
  • Facebook
  • Google +1

Posts navigation

← Nextgen Gallery Instruction Manual & Help
Quick, Easy, and Cheap VPN for Mac →
  • Search

  • Great Stuff

  • Friends

    The best company for computer repair in Asheville you will find are my buddies at Christopher's Computers..
  • All About You

    IP Address: 107.22.25.119
    Place: , ,
    Zip Code:
    Lat:
    Long:

  • Donate

    If you found something useful here on Geekamongus, please consider donating some mulah. It's quite a good motivator!
  • Categories

    • 0-day
    • Apple
    • Apps
    • Audio
    • Backups
    • Black Hat
    • CPanel
    • CSS
    • Databases
    • Email
    • Facebook
    • Firefox
    • Freeware
    • Games
    • Geeky Greats
    • Google
    • Hacks
    • HTML
    • jQuery
    • Linux
    • Mac
    • Microsoft
    • MySQL
    • Network
    • News
    • Photoshop
    • Practical Security
    • Privacy
    • RedHat
    • Samba
    • Security
    • Social Networking
    • Spam
    • SSH
    • Tweaks
    • Uncategorized
    • Virtualization
    • VNC
    • Web Browsers
    • Web Design
    • WordPress
  • Archives

    • March 2013
    • January 2013
    • December 2012
    • August 2012
    • June 2012
    • May 2012
    • December 2011
    • May 2011
    • April 2011
    • March 2011
    • January 2011
    • July 2010
    • June 2010
    • May 2010
    • March 2010
    • January 2010
    • December 2009
    • November 2009
    • October 2009
    • September 2009
    • August 2009
    • June 2009
    • May 2009
    • April 2009
    • March 2009
    • February 2009
    • January 2009
    • December 2008
    • November 2008
    • October 2008
    • September 2008
    • August 2008
Proudly powered by WordPress Theme: Parament by Automattic.