Major bug in PHP

Discussion in 'News and Article Comments' started by Addis, Dec 21, 2004.

  1. Addis

    Addis The King

    Likes Received:
    91
    Trophy Points:
    48
    A serious bug in the popular PHP development language can leave databases wide open to intrusion if the proper security steps aren't taken.

    The exploit, which affects php versions prior to 4.3.10 or 5.0.3, uses errors in the way that serialisation and realpath commands are handled to gain escalated privileges, bypass some security restrictions and compromise a vulnerable system. Many web administrators are suffering problems from hackers that have been quick to do what damage they can.

    The solution to the exploit is to upgrade to the latest version of php - either 4.3.10 or 5.0.3, depending on which thread you are running. The 4.3.10 build also includes some 5.x bugfixes and features which have been ported backwards.

    Hmm don't know anything about this but isn't this site based on PHP... :eek:
    The Inquirer
     
  2. Sniper

    Sniper Administrator Staff Member

    Likes Received:
    59
    Trophy Points:
    63
    I don't think the host runs any of those versions! If so I will inform them now! thx addis!

    I just bought a book to learn PHP and MySQL in my spare time if any.
     
  3. Addis

    Addis The King

    Likes Received:
    91
    Trophy Points:
    48
    Hehe I was looking in PC World at a book on PHP, MySQL and Dreamweaver but decided to go for networking instead. Dunno why but reading from a book in my free time always makes thing stick in my head better than from a screen.
     
  4. Sniper

    Sniper Administrator Staff Member

    Likes Received:
    59
    Trophy Points:
    63
    ah networking I need to read more about it! but always wanted to learn php/mysql! well the php part is harder!
     

Share This Page