Nytro Posted March 25, 2011 Report Posted March 25, 2011 Oddities of PHP file access in WindowsAbstractNotorious web development language, PHP, is under constant watch of the hackers, securityresearchers and other persons who just love to tinker around some stuff. Numerous vulnerabilities andbugs of PHP interpreter regularly highlights bug-tracks, wakes up administrators and burdens the mindsof web site owners. And we never can know what nifty tricks PHP interpreter had reserved for our nextday. In this paper we will describe details about how PHP treats file names on Windows operatingsystems, regarding the presence of different fuzzy characters.Contents1. The prologue of current research...........................................................................................................42. Investigating our fuzzing results............................................................................................................53. Collecting together all the known tricks to access files in Windows.....................................................94. More exploitation variations................................................................................................................135. Conclusion..........................................................................................................................................146. References...........................................................................................................................................15Download:http://onsec.ru/onsec.whitepaper-02.eng.pdf Quote