3 ms·
I haven't heard it used in the "wild" yet, and it's not a MITM attack. Just shows how useless this verification method is - if you're hitting a PHP built site -
by Monotoko 11y ago
I haven't heard it used in the "wild" yet, and it's not a MITM attack. Just shows how useless this verification method is - if you're hitting a PHP built site - a relatively simple hack would be to find a PHP page that allows you to upload something, most hosts don't upload to the root but I imagine it'd be trivial to use the upload process against itself.
I know W3schools is often thought of as useless, but for the upload script example on there there is no validation: http://www.w3schools.com/php/php_file_upload.asp http://www.w3schools.com/php/php_file_upload.asp
I imagine uploading something called "../verifyme.txt" would upload it to the root of the website.
- baby 11y agoit has to be uploaded to a specific path the server gives you "/.acme_something/something...". But I agree that it's not really perfect...
- Dylan16807 11y agoWell, if the PHP site gives you full control over the domain, then you have full control over the domain, don't you? The security issue there is not the fact that MitM becomes slightly easier, it's that you can alter the site for all visitors and don't need MitM.