Video wird geladen...

Video konnte nicht geladen werden

Zur Startseite

Improperly Secured PHP Functions Can Lead to Full System Acces 🧵

11,993 Aufrufe • vor 1 Jahr •via X (Twitter)

5 Kommentare

Profilbild von OffSec
OffSecvor 1 Jahr

A vulnerable PHP function, system(), allowed us to execute arbitrary commands on the target. By capturing a generated password and modifying the request, we successfully executed id—proving remote code execution (RCE) was possible.

Profilbild von OffSec
OffSecvor 1 Jahr

What this means: ⭕️ Attackers can escalate this to a reverse shell, gaining full control over the system. ⭕️ Web apps that allow unsanitized user input in system commands are high-risk targets.

Profilbild von OffSec
OffSecvor 1 Jahr

Key takeaway: If you're securing web applications, always assume input can be weaponized and lock down execution paths before attackers do. Prevent this by disabling functions (system, exec, shell_exec) and implementing proper input validation.

Profilbild von OffSec
OffSecvor 1 Jahr

For more tutorials, join OffSec Live: 🗓️ Friday, February 14th, 2025 at 6:00 p.m. ET 💻 PG Practice Machine: Shiftdel 🎯 Topic: PEN-200 - Common Web Application Attacks, Locating Public Exploits and Linux Privileges Escalation

Profilbild von 毛玉真
毛玉真vor 1 Jahr

确实,PHP函数如果没有妥善保护,可能会导致系统被完全访问。这提醒我们在开发中要加强安全措施,确保代码安全,避免潜在风险。💰

Ähnliche Videos