Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

.gif file that starts straight with '<?php' instead of 'GIF89a.' #13

Open
peterpeter opened this issue May 27, 2016 · 0 comments
Open

Comments

@peterpeter
Copy link

Hi
A collegue discovered two manipulatetd gif files in his (Joomla-) template image folder, that starts straight with
<?php
instead of the used jamss-pattern
GIF89a.*[\r\n]*.*<\?php
followed by plain php-code (no eval/gzip/base64_encode.....)

As the patterns are file-extension indepent, and this is the future format of manipulatet gif's, that could be faced by adding a additional 'include/exclude file-extension' entry/entries in the patterns arrays, that can be used as an additional condition in the scan_file() function.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant