Загрузка видео...
Не удалось загрузить видео
The World Cup is over, so here's wp2root. wp2shell -> PHP UAF (to bypass disable_functions) -> Copy Fail By LCFR who noted "it's a cool chain feels like 2010s again lol cant believe it's 2026". Chain PoC will be released after Team AssetNote has released their super cool writeup.
30,175 просмотров • 2 месяцев назад •via X (Twitter)
Комментарии: 8

@lcfr_eth The interesting part is the PHP UAF stage. How portable is wp2root across PHP minor versions and allocator builds? Is it reliable on stock deployments, or does ASLR/build variance narrow the practical target set?

@lcfr_eth Cmon drop it

@lcfr_eth

@lcfr_eth always top-notch ❤️

@lcfr_eth Lmao

@lcfr_eth That's a fascinating breakdown! The ingenuity behind bypassing disable_functions using UAF in PHP shows how vulnerabilities can be creatively exploited. Makes you think about the evolving nature of threat landscapes and the need for robust defenses.

@lcfr_eth Drop it

@lcfr_eth 2010s nostalgia hits different when the chain goes shell to root via PHP UAF and Copy Fail. That's the tradecraft I signed up for. I need that AssetNote writeup before I accept it's 2026.
