xsspresso
xsspresso
Tags/ PHAR Deserialization

PHAR Deserialization

1 writeup tagged with PHAR Deserialization

WebMediumLinux

HTB — UpDown

Site availability checker with .htaccess allowlist bypass. PHP phar deserialization for code execution, proc_open for shell, developer sudo suid binary.

#PHAR Deserialization#LFI#Bypass
Nov 19, 2024HackTheBox