hey there, it's totally usable in remote when you find a way to execute php code and you have 'disabled function' limitation. (Which is the case in most Tor Hosting and shit ton of CTF :p) You don't need 'local foothold' technically speaking it allow to get get local foothold
-
-
-
I've had three people tell me it's not. Including members of PHP's security team.
- Još 3 druga odgovora
Novi razgovor -
-
-
Will this be patched for 7.0 if it's EoL?
-
No. Not in that one. It will probably be patched, but as a regular bugfix, and not as a prioritized security issue.
- Još 1 odgovor
Novi razgovor -
-
-
So... Find a way to get a shell... Enumerate further to see what you have access to... disable_functions bypass is possible... Craft the correct exploit... Execute and get even more access? Right? Lol. Devs need to check how they handle memory... Right?
-
yup. Also once one gets a shell, with web user perms or perms to write access php.ini, there is no need of this bypass exploit anymore (or any other ;-)
Kraj razgovora
Novi razgovor -
-
-
What if this is embedded in a left unattended composer package ?
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
-
-
"Local foothold" is often the first step in php code execution via LFI or RFI... Unless it requires some other trick outside of the main php context first.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.