Alex Rivera | Logout

Can a php shell be injected into an image? How would this work?

Asked 2011-02-24T08:15:21.460
11

I remember seeing an exploit for an image uploading function, which consisted of hiding malicious php code inside a tiff image.

I'm making my own image uploading script, and I assume I'll have to protect myself from this possibility. Except, that I have no idea how it would work. Does anyone know how a php shell hidden inside an image would execute itself? Would it need to be loaded in a certain way?

Thanks.

Edit
Report

2 Answers

3

There are some methods to protect yourself from such tricks. Check them out here

Also read this article which explains the attack and ways to tackle it.

The main point stressed in these is the use of basename function of php to defer such attacks.

answered 2011-02-24T08:30:00.460
0

Yes it can. Make a tif file (php-code.tif) with the following code

<?php 

  die("TIF file malicious code works");

Then in another script make include 'php-code.tif';

See for yourself what happends...

Yes include this would mean the attacker has access to your server OR you uploaded the file yourself as a theme or plugin for a cms... oups!


Now the 2nd part for protecting from such attacks, well I could not find yet a reliable solution, which would work with most CMSs and not involve denying directory listings. Still looking...

answered 2012-05-17T09:01:25.763

Your Answer