PHP apps plagued by Mark of the Beast bug
theregister.co.uk
theregister.co.uk
Either address a technical crowd, and use proper technical terms, or use plain language anyone can understand.
"GET protocol"?
"adding a “-ffloat-store” flag to CFLAGS"??? Do they even know what this means?
Also, yesterday, there was a poster in here claiming that PHP's json_decode() of an object like {"motb":"2.22507385851e-308"} would trigger the vulnerability whether the number was enclosed in quotes or not. I have since determined that this claim is false, json_decode() did not trigger the problem with or even without the quotes. In fact, the only way I was able to reliably cause the crash was by casting variables from the $_REQUEST array as float - a behavior that can be safeguarded against pretty easily.
Obviously, this is a serious issue, but it's an attack apps can be hardened against with minimal effort. For comparison, a buffer overflow vuln on the string type would be much, much more disastrous. So we're going to have to run an extra line of input sanitization for a while, that's all.
foreach($_REQUEST as $var=>$val){
if($val=='22250738585072011')
$_REQUEST[$var] = NULL;
} if(substr(str_replace('.', '', $val), 0, 11)=='22250738585'))
Feel free to post the test you do.What it actually means: http://en.wikipedia.org/wiki/Number_of_the_Beast