<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: security hole for files with a dot at the end</title>
	<atom:link href="http://verens.com/2008/10/13/security-hole-for-files-with-a-dot-at-the-end/feed/" rel="self" type="application/rss+xml" />
	<link>http://verens.com/2008/10/13/security-hole-for-files-with-a-dot-at-the-end/</link>
	<description>klog - Kae&#039;s Log</description>
	<lastBuildDate>Mon, 21 May 2012 21:11:58 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<item>
		<title>By: Arjan</title>
		<link>http://verens.com/2008/10/13/security-hole-for-files-with-a-dot-at-the-end/#comment-1158</link>
		<dc:creator>Arjan</dc:creator>
		<pubDate>Fri, 17 Oct 2008 11:43:27 +0000</pubDate>
		<guid isPermaLink="false">http://verens.com/?p=504#comment-1158</guid>
		<description>Thanks for the update, I guess we will have to update our Apache configurations to include your FilesMatch fix.</description>
		<content:encoded><![CDATA[<p>Thanks for the update, I guess we will have to update our Apache configurations to include your FilesMatch fix.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kae Verens</title>
		<link>http://verens.com/2008/10/13/security-hole-for-files-with-a-dot-at-the-end/#comment-1157</link>
		<dc:creator>Kae Verens</dc:creator>
		<pubDate>Fri, 17 Oct 2008 11:41:07 +0000</pubDate>
		<guid isPermaLink="false">http://verens.com/?p=504#comment-1157</guid>
		<description>I also reported it to the Fedora PHP list and was again told that it is a feature required for MultiViews.

In short, this will not be fixed ever, so a lot of PHP scripts will need to be rewritten.</description>
		<content:encoded><![CDATA[<p>I also reported it to the Fedora PHP list and was again told that it is a feature required for MultiViews.</p>
<p>In short, this will not be fixed ever, so a lot of PHP scripts will need to be rewritten.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kae Verens</title>
		<link>http://verens.com/2008/10/13/security-hole-for-files-with-a-dot-at-the-end/#comment-1156</link>
		<dc:creator>Kae Verens</dc:creator>
		<pubDate>Fri, 17 Oct 2008 11:40:17 +0000</pubDate>
		<guid isPermaLink="false">http://verens.com/?p=504#comment-1156</guid>
		<description>I reported it to their security mailinglist. I was told that it is a &quot;feature&quot; necessary MultiViews. Personally, I don&#039;t use MultiViews, and would prefer that this &quot;feature&quot; is removed.

Interestingly, this can be exploited on image-upload scripts which allow images to be viewed from their original file. Simply create a PHP file, rename it &quot;image.php.jpg&quot; and upload it. Apache will treat the file as if it is PHP (not JPG) and will run it... This will probably affect quite a lot of scripts.</description>
		<content:encoded><![CDATA[<p>I reported it to their security mailinglist. I was told that it is a &#8220;feature&#8221; necessary MultiViews. Personally, I don&#8217;t use MultiViews, and would prefer that this &#8220;feature&#8221; is removed.</p>
<p>Interestingly, this can be exploited on image-upload scripts which allow images to be viewed from their original file. Simply create a PHP file, rename it &#8220;image.php.jpg&#8221; and upload it. Apache will treat the file as if it is PHP (not JPG) and will run it&#8230; This will probably affect quite a lot of scripts.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Arjan</title>
		<link>http://verens.com/2008/10/13/security-hole-for-files-with-a-dot-at-the-end/#comment-1155</link>
		<dc:creator>Arjan</dc:creator>
		<pubDate>Fri, 17 Oct 2008 11:36:35 +0000</pubDate>
		<guid isPermaLink="false">http://verens.com/?p=504#comment-1155</guid>
		<description>This is very disturbing news! Did you already report this to the Apache Foundation or its bugzilla? I think this breaks the security of a lot upload pages.</description>
		<content:encoded><![CDATA[<p>This is very disturbing news! Did you already report this to the Apache Foundation or its bugzilla? I think this breaks the security of a lot upload pages.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

