Orlando Indian Community - OrlandoIndian.com
| | | | | | | | | | | |
 


 

Hackers using bug in PHP7 to hijack web servers: Report

Russian Federation,Technology

Author : Indo Asian News Service

International, National, Russian Federation, Technology Read Latest News and Articles

Share With Your Friends



Add an Article

View All Contributions

Add To My Favorite

Add A Picture

Moscow, Oct 28 (IANS) Russia-based security researcher Emil 'Neex Lerner has disclosed a remote-code execution vulnerability in PHP 7 - the newest iteration of the massively widespread net growth language.

PHP is a server side scripting language that is used to develop static websites, dynamic websites or web applications. It forms the basis of popular content management systems like WordPress, Drupal, as well as Facebook (kinda). Due to this, it is a huge deal whenever someone wants to identify a security vulnerability within it.

With this vulnerability, which has the CVE-ID of 2019-11043, an attacker may drive a distant net server to execute their very own arbitrary code just by accessing a crafted URL. The attacker only needs to add "?a=" to the website address, followed by their payload, The Next Web (TNW) reported on Sunday.

As per the report, this attack drastically lowers the barrier to entry for hacking a website which even a non-technical user could abuse.

The vulnerability only impacts servers using the NGINX web server with the PHP-FPM extension and users who are unable to update their PHP install can mitigate the problem by setting a rule within the standard PHP ModSecurity firewall.

--IANS

wh/bc


Copyright and Disclaimer: All news and images appearing in our news section, search engines and social media are provided by IANS. If you face any issues related to the content/images, please contact our news service provider directly. We are not liable/responsible for any content/images related to the news service provider.


Latest News

View More News


More News Articles

IPL 2024: All it needs is to win a couple of games and you are back in contention, says Rashid Khan

IPL 2024: All it needs is to win a couple of games and you are back in contention, says Rashid Khan

Aditi Rao Hydari's b'day wish for 'manicorn' Siddharth: 'Endless laughter, happiness'

Aditi Rao Hydari's b'day wish for 'manicorn' Siddharth: 'Endless laughter, happiness'

Why Vidya Malvade says she felt she would become 6 feet tall by end of 'Ruslaan' shoot