Serious ImageMagick Zero-Day Vulnerabilities – ImageTragick?

The New Acunetix V12 Engine


So another vulnerability with a name and a logo – ImageTragick? At least this time it’s pretty dangerous, a bunch of ImageMagick Zero-Day vulnerabilities have been announced including one that can leave you susceptible to remote code execution.

It’s pretty widely used software too and very public, if you use an app online that lets you upload images and they get cropped/resized then it’s probably using ImageMagick or something similar on the back-end (PHP often uses GD).

Serious ImageMagick Zero-Day Vulnerabilities - ImageTragick?

I know some organisations that use it in their Ruby apps to deal with user avatar uploads, and they will be very open to this channel of ownage. Of course if you’re already smart and using a third party service to do it like Cloudinary or ImgIX – you are safe.

A wildly popular software tool used by websites to process people’s photos can be exploited to execute malicious code on servers and leak server-side files.

Security bugs in the software are apparently being exploited in the wild right now to compromise at-risk systems. Patches to address the vulnerabilities are available in the latest source code – but are incomplete and have not been officially released, we’re told.

Whenever you upload a profile photo, a gallery of snaps, or a silly meme to a website, there’s an extremely high chance that the site is using ImageMagick, an open-source collection of image processing tools, to resize, crop and tweak the pictures.

By feeding booby-trapped data – such as a poisoned selfie – to web services using ImageMagick, it may be possible to execute malicious code on the website’s server. From there hackers can start infiltrating the system to steal secrets, snoop on people’s accounts, and so on.

Source: The Register


The exploit is in use in the wild as it’s fairly trivial and current patches are incomplete. It seems like the details leaked out before the proper patches could be developed, tested and rolled out – they are expected to come this weekend though.

The flaw itself somehow seems to be related to these insecure delegates used by ImageMagick.

How to Protect against it

1. Verify that all image files begin with the expected “magic bytes” corresponding to the image file types you support before sending them to ImageMagick for processing. (see FAQ for more info)
2. Use a policy file to disable the vulnerable ImageMagick coders. The global policy for ImageMagick is usually found in “/etc/ImageMagick”. The below policy.xml example will disable the coders EPHEMERAL, URL, MVG, and MSL.

An example policy.xml:

Do note, this is not a complete protection and you need to apply the patches as soon as they are released.

This has been assigned – CVE-2016–3714 and if you want to read a more technical look at the issues, read this thread – Re: ImageMagick Is On Fire — CVE-2016-3714 and this – Remote code execution vulnerability in ImageMagick.

Posted in: Exploits/Vulnerabilities, Web Hacking


Latest Posts:


Malcom - Malware Communication Analyzer Malcom – Malware Communication Analyzer
Malcom is a Malware Communication Analyzer designed to analyze a system's network communication using graphical representations of network traffic.
WepAttack - WLAN 802.11 WEP Key Hacking Tool WepAttack – WLAN 802.11 WEP Key Hacking Tool
WepAttack is a WLAN open source Linux WEP key hacking tool for breaking 802.11 WEP keys using a wordlist based dictionary attack.
Eraser - Windows Secure Erase Hard Drive Wiper Eraser – Windows Secure Erase Hard Drive Wiper
Eraser is a hard drive wiper for Windows which allows you to run a secure erase and completely remove sensitive data from your hard drive by overwriting it several times with carefully selected patterns.
Insecure software versions are a problem Web Security Stats Show XSS & Outdated Software Are Major Problems
Netsparker just published some anonymized Web Security Stats about the security vulnerabilities their online solution identified on their users’ web applications and web services during the last 3 years.
CTFR - Abuse Certificate Transparency Logs For HTTPS Subdomains CTFR – Abuse Certificate Transparency Logs For HTTPS Subdomains
CTFR is a Python-based tool to Abuse Certificate Transparency Logs to get subdomains from a HTTPS website in a few seconds.
testssl.sh - Test SSL Security Including Ciphers, Protocols & Detect Flaws testssl.sh – Test SSL Security Including Ciphers, Protocols & Detect Flaws
testssl.sh is a free command line tool to test SSL security, it checks a server's service on any port for the support of TLS/SSL ciphers, protocols as well as recent cryptographic flaws and more.


Comments are closed.