æ¨å¤ã«ãéæ³å°å¥³ã¢ãããâãã®ã«æ»æã観測ãã¾ãããéæ³å°å¥³ã¢ãããâãã®ã«ã¨ã¯ãPoCã®ã½ã¼ã¹ã³ã¼ãã«Â Apache Magica by Kingcope ã¨ã³ã¡ã³ãããã¦ãããã¨ã«ç±æ¥ãã¦ãã¾ãï¼ã¨ããããç§ããã訳ãã¾ããwï¼ã ããã¯10æ29æ¥ã«PoCãçºè¡¨ãããPHP-CGIæ»æ(CVE-2012-1823)ã®å¤ç¨®ã§ããå¾æ¥ã®PHP-CGIæ»æã¯ãCGIçPHPãåä½ããç°å¢ã§ãPHPã¹ã¯ãªããï¼ä¸èº«ã¯ãªãã§ãããï¼ã«å¯¾ããæ»æã§ããããéæ³å°å¥³ã¢ããããã®ã«ã®æ¹ã¯ã/cgi-bin/ã«ç½®ãããPHPå¦çç³»ï¼php-cgiãªã©ï¼ã«ç´æ¥æ»æãããã®ã§ãã CGIçPHPãè¨ç½®ããæ¹æ³ã¯è¤æ°ããã¾ããããã使ãããæ¹æ³ã¨ãã¦Apacheã®ãªãã¤ã¬ã¯ãã«ããPHPã¹ã¯ãªãããPHPå¦çç³»ã«å®è¡ãããæ¹æ³ãããã¾ãããã®å ´åã/cgi-bin/php-cgiãªã©ã¨ãã¦PHPå¦çç³»ãå ¬é
{{#tags}}- {{label}}
{{/tags}}