HomeSecurityResearchers Find PHP Zero-Day Aimed at Hacking Pornhub

Researchers find PHP Zero-Day aimed at hacking Pornhub

A team of three researchers went on to search for and discover a PHP zero-day so they could hack Pornhub as part of its official bug bounty program.

The route the three took to hack Pornhub is something you don't usually see in a typical security investigation. Because Pornhub's servers were somewhat secure from common attack vectors, the researchers were forced to get creative with their routine attack.

Researchers find PHP Zero-Day aimed at hacking Pornhub

What emerged was a zero-day in PHP, a programming language used to power the Pornhub website.

The issue (CVE-2016-5771 / CVE-2016-5773) is a use-after-free vulnerability that occurs when PHP's garbage collection algorithm interacts with other specific PHP objects.

One of these is a PHP unserialize function, which handles data taken from user-provided objects, such as what the user uploads, and moves it to various parts of the server for processing.

Exploiting this zero-day, the three researchers, Dario Weißer (@haxonaut), cutz, and Ruslan Habalov (@evonide), were able to leak the address of the server's POST data.

This allowed them to create a payload, which used memory freed by the PHP garbage collector after the PHP unserialize component had done its job, which executed malicious code on the Pornhub server.

This exploitation was made extra difficult by the fact that Pornhub used a custom-compiled version of PHP, but the researchers managed to do it anyway.

The PHP zero-day they discovered affects all PHP versions 5.3 and above, which the PHP project has since patched.

Since the researchers were able to achieve a PornHub RCE (Remote Code Execution), they received one of Pornhub's highest bug bounties, with an amount of around $20,000.

Additionally, HackerOne's Internet Bounty Bug Committee awarded the researchers an additional $2,000 for the discovery and proper disclosure of the PHP zero-day.

To understand the enormous amount of work that went into this theoretical attack on Pornhub servers, the researchers wrote two incredibly long and extremely detailed blog posts on the technical details of this attack, with a third one announced for next week.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS