Advanced PHP Deserialization - Phar Files

Advanced PHP Deserialization - Phar Files

IppSec

5 лет назад

41,608 Просмотров

Ссылки и html тэги не поддерживаются


Комментарии:

@nickomode8948
@nickomode8948 - 23.12.2019 04:50

when will you do smasher2? is there going to be unintended routes in the video

Ответить
@SomeGuyInSandy
@SomeGuyInSandy - 23.12.2019 07:02

Thank you for including a way to eliminate this vulnerability!

Ответить
@DividesByZer0
@DividesByZer0 - 23.12.2019 07:22

I love when you do videos that go into specific subjects like this. 👍

Ответить
@neoXXquick
@neoXXquick - 23.12.2019 14:48

Amazing video.. i would like if you could continue this series..

Ответить
@khneo
@khneo - 23.12.2019 15:25

Thank you, your last video are really cool ! I hope you will do more like that !

I just have a question : in a black box testing, is there a way to know that there is a vulnerability or do you just try it and see if it works ?

Ответить
@supercoolgames8218
@supercoolgames8218 - 24.12.2019 07:42

Thanks heaps for this, very interesting.

I am just wondering, how are the methods "unlink", "md5sum" triggering the destruct magic method of the object you're creating? Is is apart of the phar:// read processing? When is the object unset?

When is it possible to use phar://, only with methods that involve reading data?

Ответить
@khalat173
@khalat173 - 26.12.2019 06:07

Hi. Would be great to have a little bit more volume on the audio. Otherwise, really great.

Ответить
@Matthe9256
@Matthe9256 - 14.06.2020 04:25

What application do you use to edit phar file

Ответить
@TheMrchement
@TheMrchement - 14.06.2020 22:51

Can you teach me step by step for ethical hacking or pentesting

Ответить
@0xc0ffee_
@0xc0ffee_ - 10.07.2020 02:37

You can't do this if you don't know the name of the class that's already present on the server, right?

Ответить
@adhilazeez6039
@adhilazeez6039 - 13.02.2021 21:44

Great content 👍. All your videos are awsome. And really thanks for your support 👍

Ответить
@UmairAli
@UmairAli - 01.11.2021 16:02

You're My Inspiration ♥ :)

Ответить
@rawbytes7356
@rawbytes7356 - 17.09.2022 00:08

Its been 2yrs of this video,learned a lot from it. But it somehow doesn't work with php 8.1,it works good with php 7.4 . I think they changed something in new update so it doesn't work. I spend to find why it is not working (I was working with php8.1),then ran it with php7.4 and voila,magic happened. Thanks for such quality learning meterial...

Ответить