CyberWire Daily

ThinkPHP exploit from Asia-Pacific region goes global. [Research Saturday]

Mar 16, 2019 · 14 min · Season 3 · Episode 77
0:00-14:08

Streams straight from the publisher. podnod never proxies or re-hosts episode audio.

Akamai's Larry Cashdollar joins us to describe an exploit he recently came across while researching MageCart incidents. It's a remote command execution vulnerability affecting ThinkPHP, a popular web framework.

The original research can be found here:

https://blogs.akamai.com/sitr/2019/01/thinkphp-exploit-actively-exploited-in-the-wild.html