post-feature-image
HomeTech News

Yahoo Bugs Gain Root Access Through Php Eval() Function

Security researcher Ebrahim Hegazy found that by manipulating one of the URLs used Yahoo Mail settings, it can execute system commands remo...

Security researcher Ebrahim Hegazy found that by manipulating one of the URLs used Yahoo Mail settings, it can execute system commands remotely. Yahoo end, parameter is used php eval() function, which takes a string and runs it as php code. PHP function documentation explicitly warns against its use, where possible, and where there is no other choice transmitted eval( ) is an approved care.

This verification process seems to be the case can use a combination of print() and system( ) function to execute commands and return the results. Currently, Hegazy was able to execute any code from the same privileges originally launched a web server, including a list of running processes , logged-in users and content subscribers.

However, he later discovered kernel used outdated and the vulnerabilities that could have allowed him to escalate the privileges of the web server account and gain root access.
Name

Apple Apps E-Reader Facebook Games Google Internet Laptop Microsoft Phablet Smartphone Social Network Tablet Tech News
false
ltr
item
Gadgets Corner : Yahoo Bugs Gain Root Access Through Php Eval() Function
Yahoo Bugs Gain Root Access Through Php Eval() Function
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj_wrgaiaB3cxkVmX3D4XXdpZIgxPe-TOyqj18dAwk12bJEpXasX4BdQqbvsE3jUXIUiiNRZyq9PCp5ZEzJKrsnEBnVw7wizkoQSBqlbmyjH-HKpooN8MS-dDtJ0O51OC4Wh-LJdsLF3Gcs/s1600/yahoo.jpg
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj_wrgaiaB3cxkVmX3D4XXdpZIgxPe-TOyqj18dAwk12bJEpXasX4BdQqbvsE3jUXIUiiNRZyq9PCp5ZEzJKrsnEBnVw7wizkoQSBqlbmyjH-HKpooN8MS-dDtJ0O51OC4Wh-LJdsLF3Gcs/s72-c/yahoo.jpg
Gadgets Corner
http://cmdcorner.blogspot.com/2014/01/yahoo-bugs-gain-root-access-though-php.html
http://cmdcorner.blogspot.com/
http://cmdcorner.blogspot.com/
http://cmdcorner.blogspot.com/2014/01/yahoo-bugs-gain-root-access-though-php.html
true
2424653965478038045
UTF-8
Not found any posts VIEW ALL Readmore Reply Cancel reply Delete By Home PAGES POSTS View All RECOMMENDED FOR YOU LABEL ARCHIVE SEARCH Not found any post match with your request Back Home Sunday Monday Tuesday Wednesday Thursday Friday Saturday Sun Mon Tue Wed Thu Fri Sat January February March April May June July August September October November December Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec just now 1 minute ago $$1$$ minutes ago 1 hour ago $$1$$ hours ago Yesterday $$1$$ days ago $$1$$ weeks ago more than 5 weeks ago