I’ve updated the Apache Source Defense patch to correctly match extensions. Prior to these changes any file that contained a ‘.php’ extension would be included, such as .php.txt etc. I’ve now corrected this so it will only match the last extension in a file. If you are currently using this and expect it to protect against these situations, please add additional extensions to the patch to make sure you’re protected (I hold no liability for this not working as advertised). If you run across any problem, bugs, missing features please let me know.
Leave a reply