10

2023年春秋杯网络安全联赛春季赛 web php_again [PHP 8.2.2 OPcache Binary Webshell...

 1 year ago
source link: https://fdlucifer.github.io/2023/07/01/2023-chunqiubei-spring-php-again/
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.
neoserver,ios ssh client

同样是在ichunqiu CTF大本营刷题的时候碰到一道高质量的web题,也比较有实战价值,比赛中算是web里耗时较长的的。网上已经有一些公开的writeup,但是为了加深理解记忆,故记录一篇blog。

其中包括一些网上没公开的一些CVE-2022-42919 LPE exp及PHP 8.2.2 OPcache Binary Webshell的利用细节。

PHP 8.2.2 OPcache Binary Webshell

CVE-2022-42919 LPE


Recommend

About Joyk


Aggregate valuable and interesting links.
Joyk means Joy of geeK