test.txt: PHP Exploit in Server Logs

I noticed some strange requests in my Apache logs today. People were referencing external files named “test.txt” in arguments to PHP scripts. It seems to be a remote execution exploit targeting Windows servers, but I’m not sure which piece of software is at risk. I’ll update this page if I find it’s targeting some specific software.

I saved a copy for posterity, after replacing the opening PHP brace with “<-- php.”

Posted 2008-02-05 at 15:33
Categories Web
Tags
Short URL http://603.be/8Zlhg4
Canonical URL http://sixohthree.com/443/php

Respond

XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>