PHP-FPM 7.1.3 listening on port 9000 without restriction: a client speaking FastCGI directly sets the SCRIPT_FILENAME of an existing PHP file and the PHP_VALUE / PHP_ADMIN_VALUE parameters (auto_prepend_file=php://input, allow_url_include=On), so the request body runs as PHP.
Pas commencéDockercommit f4bfff6x86_64 · aarch64Secret
Talk FastCGI to the exposed PHP-FPM port to run PHP code and get a shell.
Le brief de ce lab se trouve dans son dépôt.