iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
In 2016, security researchers said they used two previously unknown flaws in PHP to achieve remote code execution while auditing PornHub. They reported the vulnerabilities through the site’s bug bounty process; the reports do not say the team stole user data or carried out a public breach.
What happened during the PornHub security audit?
Researchers Dario Weißer, Ruslan Habalov, and an expert known as “cutz” were auditing PornHub when they found a way to exploit two PHP vulnerabilities. The bugs were in PHP itself, rather than a flaw unique to PornHub’s application. The team reported the issue through PornHub’s bug bounty program. SecurityWeek reported that PornHub fixed the problem within hours of receiving the submission. SecurityWeek’s July 25, 2016 report identifies the vulnerabilities as CVE-2016-5771 and CVE-2016-5773.
The researchers said they achieved remote code execution (RCE)—the ability to make a remote system run code—on the site. That is a serious potential impact, but it is not evidence that they dumped PornHub’s database, accessed user records, or leaked source code. Their published account describes exploitation during an audit and disclosure, not those other actions.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteHow did the PHP vulnerabilities work?
Two use-after-free flaws
Ruslan Habalov’s technical write-up describes two use-after-free vulnerabilities in PHP’s cycle garbage collector. A use-after-free happens when software continues to use a portion of memory after it has been released. Such a bug can corrupt memory and, under the right conditions, be turned into code execution.
#1 Best Overall
Habalov traces the bugs to interactions between garbage collection and particular PHP objects. One involved an ArrayObject in PHP 5 branches before PHP 7; the other affected PHP 5 and PHP 7 branches at the time. The exploitation was not simply a matter of calling one function: the researchers used PHP’s unserialize input-handling path to reach the vulnerable behavior, then did additional work to make exploitation reliable.
Why unserialize mattered
PHP’s unserialize function reconstructs PHP values and objects from serialized data. Habalov says the relevant path could be reached remotely, allowing attacker-controlled input to trigger the underlying memory-safety bugs. The important distinction is that unserialize was part of the route to the vulnerabilities; the account does not describe the function by itself as the cause of the compromise.
Rank #2
Habalov’s general secure-coding advice was: “you should never use unserialize with user input and rather rely on less complex serialization methods like JSON.” For developers, the broader lesson is to avoid deserializing untrusted data where possible and to keep the PHP runtime patched. Choosing a different format does not remove the need to validate inputs and secure application logic.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Which PHP versions were affected, and what fixed them?
The vulnerabilities affected historical PHP branches, and the two flaws did not have identical version ranges. SecurityWeek reported that PHP fixes were released on June 23, 2016, in PHP 7.0.8, 5.6.23, and 5.5.37. Habalov’s account says the first issue affected PHP 5 versions from 5.3 and was fixed in 5.6.23; the second affected versions from 5.3, including PHP 7, and was fixed in 5.6.23 and 7.0.8.
Those are historical release details, not a recommendation to install those old versions today. This incident report does not establish which PHP releases are currently supported or secure; administrators should consult the current official PHP security information and upgrade to a currently maintained release appropriate to their environment.
What was the disclosure and reward timeline?
- Late May 2016: SecurityWeek says the researchers discovered they could exploit the PHP flaws while auditing PornHub.
- Mid-June 2016: The vulnerabilities were disclosed to PHP developers, according to SecurityWeek.
- June 23, 2016: PHP released fixes in versions 7.0.8, 5.6.23, and 5.5.37, as reported by SecurityWeek.
- July 25, 2016: SecurityWeek’s incident report and Habalov’s technical account were published.
SecurityWeek reported a $20,000 PornHub reward. Habalov also said the Internet Bug Bounty awarded $1,000 for each of the two vulnerabilities. These are rewards associated with this 2016 disclosure, not general rates for bug bounty reports.
Rank #4
Were these the same as later PHP unserialize vulnerabilities?
No. A later Check Point report discussed three different PHP 7 unserialize vulnerabilities—CVE-2016-7479, CVE-2016-7480, and CVE-2016-7478. Its December 2016 report says two could permit full server control and one could cause denial of service. Those later issues are separate from the two vulnerabilities used in the PornHub audit.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

