Part of the solution has to do with updating your laravel
today I accidentally found my system infected due to a review made from a GoogleAds warning that my site had a virus
So you can see what it is about, look in your access log for the following line:
POST /_ignition/execute-solution
…and you will see that a few lines below you will have this other post:
POST /wJr2TTgX.php HTTP / 1.1 "200 43
To see the full explanation follow this link:
https://www.ambionics.io/blog/laravel-debug-rce
Edit: You can always edit the .env
file of what you expose to the world and put it into production mode. The vulnerability only occurs in debug mode.
与恶龙缠斗过久,自身亦成为恶龙;凝视深渊过久,深渊将回以凝视…