Skip to content

Latest commit

 

History

History
18 lines (15 loc) · 830 Bytes

README.md

File metadata and controls

18 lines (15 loc) · 830 Bytes

PHP labs and exploits for LFI with Race condition cases

Assignments for hands-on exploration of PHP vulnerabilities.

Nracer


Exploiting Nginx buffering using procfs. Exploiting realpath_cache and ways to bypass (... deleted) in realpath

Zlibber


Exploiting compress.zlib/zlib to obtain ssrf/lfi and then obtain RCE via race condition

Progresser


1. Exploiting php upload_progress using race condition and lfi followed by rce

2. Exploiting race condition using phpinfo()