Ebrahim Hegazy, an Egyptian researcher, identified a vulnerability that had infected the servers of the German telecommunications provider Telekom.
He discovered the bug on the Telekom.de website. on a subpage of the general website. The subdomain of umfragen.telekom.de seems to be changing to suggestions.telekom.de and appears to be an inactive website.
According to the researcher, the attackers could have gained full control of the Deutsche Telekom server. The vulnerability is a simple example of remote code execution (RCE) which allows the attacker to gain full control of the server by pinging ports and opening connections with malicious requests.
Having brute-forced the URL, Hegazy managed to get the address in an upload.php file. The researcher built a tool called Pemburu to do the testing.
Finally, he managed to find the URL, through the upload.php file that had pulled the data where the user had submitted it. The tool he built found the correct URL through a large set of variations and finally discovered the file that was sending the data to umfragen2.telekom.de/upload.php. This allowed Hegazy to take a closer look at the code. Through a mechanism, he obtained user input from the HTTP POST request without data sanitization and then attached the data as parameters to the PHP system function. This function is configured using the C language and allows PHP programmers to execute commands from within the application in PHP code to retrieve the results.
In general, it is not considered good practice to use this feature on any Web server. Ultimately, Hegazy stated that the gap in Telekom's security has been fixed. According to a statement published on Softpedia, he said that this research is being conducted as part of the company's bug bounty program and cost €2,000 / $2,150.

