skip to main content
10.1145/3654446.3654470acmotherconferencesArticle/Chapter ViewAbstractPublication PagesspcncConference Proceedingsconference-collections
research-article

Exploring Dynamic Class Instantiation and Imagick Extension Vulnerabilities in PHP: Insights and Techniques in Securing PHP Applications - A Comprehensive Guide to Dynamic Class Instantiation and Imagick Extension Vulnerabilities

Published:03 May 2024Publication History

ABSTRACT

As an increasing number of businesses and organizations transition their operations online, the significance of software security vulnerabilities becomes ever more critical. This paper explores the phenomenon of arbitrary code execution in PHP through the exploitation of the Imagick extension, a commonly scenario in the field of web development security. It begins with a comprehensive overview of PHP and Imagick, highlighting their integral roles in contemporary web development. The focus then shifts to the mechanics of exploiting Imagick, detailing potential methods of attack and the accompanying risks. Additionally, the paper provides a thorough analysis of strategies and practices essential for safeguarding PHP applications against such vulnerabilities. Targeted primarily at PHP developers, security analysts, and IT professionals, this study serves as a pivotal resource in understanding and mitigating security risks in web development and cybersecurity.

References

  1. United states department of commerce. 2018, June 26. NVD - CVE-2018-12712. National Institute of Standards and Technology. https://nvd.nist.gov/vuln/detail/CVE-2018-12712.Google ScholarGoogle Scholar
  2. United states department of commerce. 2023, September 13. NVD - CVE-2023-41892. National Institute of Standards and Technology. https://nvd.nist.gov/vuln/detail/CVE-2023-41892.Google ScholarGoogle Scholar
  3. United states department of commerce. 2023, September 13. NVD - CVE-2023-41892. National Institute of Standards and Technology. https://nvd.nist.gov/vuln/detail/CVE-2023-41892.Google ScholarGoogle Scholar
  4. Paul Krill. 2013, November 18. Believe the Hype: PHP Founder Backs Facebook's HipHop Technology. Infoworld. https://www.infoworld.com/article/2609877/believe-the-hype–php-founder-backs-facebook-s-hiphop-technology.html.Google ScholarGoogle Scholar
  5. Imagemagick studio llc. 1999. ImageMagick – Convert, Edit, or Compose Digital Images. ImageMagick. https://imagemagick.org.Google ScholarGoogle Scholar
  6. Imagemagick studio llc. 1999. ImageMagick – Command-Line Tools: Conjure. ImageMagick. https://imagemagick.org/script/conjure.php.Google ScholarGoogle Scholar
  7. Securityscorecard. 2023. Imagemagick: Products and Vulnerabilities. https://www.cvedetails.com/vendor/1749/Imagemagick.html.Google ScholarGoogle Scholar
  8. Stephan Venter. 2023, March 14. Remote Code Execution Attack: What It Is. TuxCare. https://tuxcare.com/blog/remote-code-execution-attack-what-it-is-how-to-protect-your-systems.Google ScholarGoogle Scholar
  9. Eamonn Neylon, Tony Hammond, Herbert Van de Sompel, Dr. Stuart Weibel. 2006, April. RFC 4452 - The “Info” URI Scheme for Information Assets with Identifiers in Public Namespaces. IETF Datatracker. https://datatracker.ietf.org/doc/html/rfc4452.Google ScholarGoogle Scholar
  10. Cristy. 1993, January. ImageMagick/MagickCore/Utility.c at Main · ImageMagick/ImageMagick. Github. https://github.com/ImageMagick/ImageMagick/blob/main/MagickCore/utility.c#L709.Google ScholarGoogle Scholar
  11. Brad bell. 2023, September 13. Remote Code Execution · Advisory · Craftcms/Cms. Github. https://github.com/craftcms/cms/security/advisories/GHSA-4w8r-3xrw-v25g.Google ScholarGoogle Scholar

Index Terms

  1. Exploring Dynamic Class Instantiation and Imagick Extension Vulnerabilities in PHP: Insights and Techniques in Securing PHP Applications - A Comprehensive Guide to Dynamic Class Instantiation and Imagick Extension Vulnerabilities

    Recommendations

    Comments

    Login options

    Check if you have access through your login credentials or your institution to get full access on this article.

    Sign in
    • Published in

      cover image ACM Other conferences
      SPCNC '23: Proceedings of the 2nd International Conference on Signal Processing, Computer Networks and Communications
      December 2023
      435 pages
      ISBN:9798400716430
      DOI:10.1145/3654446

      Copyright © 2023 ACM

      Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than the author(s) must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected].

      Publisher

      Association for Computing Machinery

      New York, NY, United States

      Publication History

      • Published: 3 May 2024

      Permissions

      Request permissions about this article.

      Request Permissions

      Check for updates

      Qualifiers

      • research-article
      • Research
      • Refereed limited
    • Article Metrics

      • Downloads (Last 12 months)0
      • Downloads (Last 6 weeks)0

      Other Metrics

    PDF Format

    View or Download as a PDF file.

    PDF

    eReader

    View online with eReader.

    eReader

    HTML Format

    View this article in HTML Format .

    View HTML Format