
5/9/2016 · John Graham-Cumming
What this post added
This post details the discovery and analysis of the ImageTragick vulnerability (CVE-2016-3714) in ImageMagick, which allows for arbitrary code execution through specially crafted image files. It describes the reconnaissance and remote access payloads used by attackers, including examples of how attackers leverage wget and python scripts to gain shell access. Cloudflare's response involved the rapid deployment of a WAF rule to protect customers from these exploits, highlighting the importance of timely threat intelligence and automated protection mechanisms.