This week HD Moore released a more generic version of an exploit for the PHP programming language. 100’s if not 1000’s of PHP driven web applications are affected. If you run a PHP v4 driven web application, check to be sure that there is no code that unserializes POST or COOKIE data. In the exploit announcement, HD Moore pointed out a Google search looking for hacked installations of the PHP forums system, phpBB.

Read more…