A Tale of openssl_seal(), PHP, and Apache2handle
Posted by deepcore on February 3, 2016 – 5:42 am
openssl_seal() is prone to use uninitialized memory that can be turned into a code execution. This document describes technical details of the journey to hijack apache2 requests. It is a very well written and thoroughly documented piece of research.
Post a reply
You must be logged in to post a comment.