, CRLF.
php-, , .
, fopen . $email , CRLF, fopen() - , .
, $fh , , .
, : http://www.securiteam.com/unixfocus/5OP0C0A8AC.html
, :
, $password , .
, $pass , strcmp true, , .
$pass $pass = fgets($fh)
CRLF fopen, URL-, , . http://your.ip.address/your-file, , $password. .
- , .
$last = fgets($fh);
$first = fgets($fh);
$pass = fgets($fh);
, , $last, $first $pass , . .
# 2 - :
../ $email, fopen, acounts/.
:
<?php
$fh = fopen("acounts/../../test.sh","r");
?>
test.sh. , $email. , , $password, .
# 3 - , .php:
, drew010, , , $email, .php, eval() php code $password , backdoor acounts/, $email, .