
CyberWire Daily
ThinkPHP exploit from Asia-Pacific region goes global. [Research Saturday]
Mar 16, 2019 · 14 min · Season 3 · Episode 77
0:00-14:08
Streams straight from the publisher. podnod never proxies or re-hosts episode audio.
Akamai's Larry Cashdollar joins us to describe an exploit he recently came across while researching MageCart incidents. It's a remote command execution vulnerability affecting ThinkPHP, a popular web framework.
The original research can be found here:
https://blogs.akamai.com/sitr/2019/01/thinkphp-exploit-actively-exploited-in-the-wild.html