Skip to main content

Greymatter Remote Command Execution Vulnerability

This paper examines a PHP injection exploit against the Greymatter WebLogging application. It begins with a detailed examination of the exploit and then reviews a sample attack against a remote network. The viewpoint is then changed to that of an administrator of the target network and the six steps of Incident Handling are reviewed. Appendixes are also provided to offer the reader a deeper understanding of the vulnerable Greymatter code and several of the tools discussed in the body of the paper.

1495 (PDF, 7.44MB)

15 Nov 2004
ByKen Rode
Share
All papers are copyrighted

No re-posting of papers is permitted

Subscribe to GIAC’s Monthly Newsletter

Receive expert insights, priority access to certifications, essential updates on regulatory changes and industry developments.

Greymatter Remote Command Execution Vulnerability