HomeSecurityRealWorld CTF Exercise: PHP zero-day vulnerability discovered allowing remote code execution

RealWorld CTF Exercise: PHP zero-day vulnerability discovered allowing remote code execution

CTF

Capture the Flag (CTF) tasks are “trials” in which security professionals participate to improve , demonstrate , and acquire skills.

In CTF competitions, security experts try to discover vulnerabilities, create exploits, toolkits, and various other things.

While participating in CTF tasks, many experts discover security issues that even the task creators themselves had not thought of. Such issues include zero-day vulnerabilities.

RealWorld CTF Exercise: PHP zero-day vulnerability discovered allowing remote code execution

PHP zero-day vulnerability found by accident

During the Realworld CTF, which took place in September, researcher Andrew Danau accidentally discovered an unusual behavior of a PHP script.

When Andrew Danau sent %0a (newline) bytes to the URL, the server's response was not normal. It returned more data than it should have. Furthermore, the amount of data was related to the number of bytes after the %0a in the URL. This behavior is usually associated with memory corruption attacks. It could also be associated with attacks that allow the leakage of sensitive personal or financial data. Finally, it could be a vulnerability that allows the execution of malicious code remotely.

Andrew's colleagues, Emil and Omar, decided to take a closer look at the issue. They were able to understand the reason for this unusual behavior and managed to create a remote code execution exploit. They concluded that it was a PHP zero-day vulnerability.

Addressing the PHP issue

Andrew's discovery is very important, mainly because the task creator himself had not thought of it. Various security solutions were already used to address the issue and it was found that the Wallarm Cloud Native WAF automatically detects the problem.

The solutions offered by Wallarm appear to be quite effective in limiting the security issue.

This is not the first time that a major discovery has been made by accident. Andrew Danau and his colleagues managed to not only discover the security issue, but also find how malicious hackers. The discovery of this PHP zero-day vulnerability is important for strengthening the protection and security of many web applications.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS