From 057217f9f246a47b0bfac4a2b160f767cc0250d0 Mon Sep 17 00:00:00 2001 From: CPol Date: Sun, 15 Nov 2020 01:09:32 +0000 Subject: [PATCH] GitBook: [master] 34 pages modified --- SUMMARY.md | 32 +++++++++---------- .../pentesting-web/php-tricks-esp/README.md | 2 +- .../README.md | 2 +- .../disable_functions-bypass-dl-function.md | 0 ...than-3.3.0-php-greater-than-5.4-exploit.md | 0 .../disable_functions-bypass-mod_cgi.md | 0 ...p-4-greater-than-4.2.0-php-5-pcntl_exec.md | 0 ..._functions-bypass-php-5.2-fopen-exploit.md | 0 ...p-5.2.3-win32std-ext-protections-bypass.md | 0 ...ons-bypass-php-5.2.4-and-5.2.5-php-curl.md | 0 ...e_functions-bypass-php-7.0-7.4-nix-only.md | 0 ...isable_functions-bypass-php-fpm-fastcgi.md | 0 ...s-bypass-php-less-than-5.2.9-on-windows.md | 0 ...perl-extension-safe_mode-bypass-exploit.md | 0 ...roc_open-and-custom-environment-exploit.md | 0 .../disable_functions-bypass-via-mem.md | 0 ...ons-php-5.2.4-ioncube-extension-exploit.md | 0 ...le_functions-php-5.x-shellshock-exploit.md | 0 18 files changed, 18 insertions(+), 18 deletions(-) rename pentesting/pentesting-web/php-tricks-esp/{php-useful-functions => php-useful-functions-disable_functions-open_basedir-bypass}/README.md (99%) rename pentesting/pentesting-web/php-tricks-esp/{php-useful-functions => php-useful-functions-disable_functions-open_basedir-bypass}/disable_functions-bypass-dl-function.md (100%) rename pentesting/pentesting-web/php-tricks-esp/{php-useful-functions => php-useful-functions-disable_functions-open_basedir-bypass}/disable_functions-bypass-imagick-less-than-3.3.0-php-greater-than-5.4-exploit.md (100%) rename pentesting/pentesting-web/php-tricks-esp/{php-useful-functions => php-useful-functions-disable_functions-open_basedir-bypass}/disable_functions-bypass-mod_cgi.md (100%) rename pentesting/pentesting-web/php-tricks-esp/{php-useful-functions => php-useful-functions-disable_functions-open_basedir-bypass}/disable_functions-bypass-php-4-greater-than-4.2.0-php-5-pcntl_exec.md (100%) rename pentesting/pentesting-web/php-tricks-esp/{php-useful-functions => php-useful-functions-disable_functions-open_basedir-bypass}/disable_functions-bypass-php-5.2-fopen-exploit.md (100%) rename pentesting/pentesting-web/php-tricks-esp/{php-useful-functions => php-useful-functions-disable_functions-open_basedir-bypass}/disable_functions-bypass-php-5.2.3-win32std-ext-protections-bypass.md (100%) rename pentesting/pentesting-web/php-tricks-esp/{php-useful-functions => php-useful-functions-disable_functions-open_basedir-bypass}/disable_functions-bypass-php-5.2.4-and-5.2.5-php-curl.md (100%) rename pentesting/pentesting-web/php-tricks-esp/{php-useful-functions => php-useful-functions-disable_functions-open_basedir-bypass}/disable_functions-bypass-php-7.0-7.4-nix-only.md (100%) rename pentesting/pentesting-web/php-tricks-esp/{php-useful-functions => php-useful-functions-disable_functions-open_basedir-bypass}/disable_functions-bypass-php-fpm-fastcgi.md (100%) rename pentesting/pentesting-web/php-tricks-esp/{php-useful-functions => php-useful-functions-disable_functions-open_basedir-bypass}/disable_functions-bypass-php-less-than-5.2.9-on-windows.md (100%) rename pentesting/pentesting-web/php-tricks-esp/{php-useful-functions => php-useful-functions-disable_functions-open_basedir-bypass}/disable_functions-bypass-php-perl-extension-safe_mode-bypass-exploit.md (100%) rename pentesting/pentesting-web/php-tricks-esp/{php-useful-functions => php-useful-functions-disable_functions-open_basedir-bypass}/disable_functions-bypass-php-safe_mode-bypass-via-proc_open-and-custom-environment-exploit.md (100%) rename pentesting/pentesting-web/php-tricks-esp/{php-useful-functions => php-useful-functions-disable_functions-open_basedir-bypass}/disable_functions-bypass-via-mem.md (100%) rename pentesting/pentesting-web/php-tricks-esp/{php-useful-functions => php-useful-functions-disable_functions-open_basedir-bypass}/disable_functions-php-5.2.4-ioncube-extension-exploit.md (100%) rename pentesting/pentesting-web/php-tricks-esp/{php-useful-functions => php-useful-functions-disable_functions-open_basedir-bypass}/disable_functions-php-5.x-shellshock-exploit.md (100%) diff --git a/SUMMARY.md b/SUMMARY.md index dd9d6bde7..5ea5a2d59 100644 --- a/SUMMARY.md +++ b/SUMMARY.md @@ -195,22 +195,22 @@ * [Joomla](pentesting/pentesting-web/joomla.md) * [Nginx](pentesting/pentesting-web/nginx.md) * [PHP Tricks \(SPA\)](pentesting/pentesting-web/php-tricks-esp/README.md) - * [PHP - Useful Functions & disable\_functiosns/open\_basedir bypass](pentesting/pentesting-web/php-tricks-esp/php-useful-functions/README.md) - * [disable\_functions bypass - php-fpm/FastCGI](pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-bypass-php-fpm-fastcgi.md) - * [disable\_functions bypass - dl function](pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-bypass-dl-function.md) - * [disable\_functions bypass - PHP 7.0-7.4 \(\*nix only\)](pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-bypass-php-7.0-7.4-nix-only.md) - * [disable\_functions bypass - Imagick <= 3.3.0 PHP >= 5.4 Exploit](pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-bypass-imagick-less-than-3.3.0-php-greater-than-5.4-exploit.md) - * [disable\_functions - PHP 5.x Shellshock Exploit](pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-php-5.x-shellshock-exploit.md) - * [disable\_functions - PHP 5.2.4 ionCube extension Exploit](pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-php-5.2.4-ioncube-extension-exploit.md) - * [disable\_functions bypass - PHP <= 5.2.9 on windows](pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-bypass-php-less-than-5.2.9-on-windows.md) - * [disable\_functions bypass - PHP 5.2.4 and 5.2.5 PHP cURL](pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-bypass-php-5.2.4-and-5.2.5-php-curl.md) - * [disable\_functions bypass - PHP safe\_mode bypass via proc\_open\(\) and custom environment Exploit](pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-bypass-php-safe_mode-bypass-via-proc_open-and-custom-environment-exploit.md) - * [disable\_functions bypass - PHP Perl Extension Safe\_mode Bypass Exploit](pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-bypass-php-perl-extension-safe_mode-bypass-exploit.md) - * [disable\_functions bypass - PHP 5.2.3 - Win32std ext Protections Bypass](pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-bypass-php-5.2.3-win32std-ext-protections-bypass.md) - * [disable\_functions bypass - PHP 5.2 - FOpen Exploit](pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-bypass-php-5.2-fopen-exploit.md) - * [disable\_functions bypass - via mem](pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-bypass-via-mem.md) - * [disable\_functions bypass - mod\_cgi](pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-bypass-mod_cgi.md) - * [disable\_functions bypass - PHP 4 >= 4.2.0, PHP 5 pcntl\_exec](pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-bypass-php-4-greater-than-4.2.0-php-5-pcntl_exec.md) + * [PHP - Useful Functions & disable\_functions/open\_basedir bypass](pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/README.md) + * [disable\_functions bypass - php-fpm/FastCGI](pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-fpm-fastcgi.md) + * [disable\_functions bypass - dl function](pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-dl-function.md) + * [disable\_functions bypass - PHP 7.0-7.4 \(\*nix only\)](pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-7.0-7.4-nix-only.md) + * [disable\_functions bypass - Imagick <= 3.3.0 PHP >= 5.4 Exploit](pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-imagick-less-than-3.3.0-php-greater-than-5.4-exploit.md) + * [disable\_functions - PHP 5.x Shellshock Exploit](pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-php-5.x-shellshock-exploit.md) + * [disable\_functions - PHP 5.2.4 ionCube extension Exploit](pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-php-5.2.4-ioncube-extension-exploit.md) + * [disable\_functions bypass - PHP <= 5.2.9 on windows](pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-less-than-5.2.9-on-windows.md) + * [disable\_functions bypass - PHP 5.2.4 and 5.2.5 PHP cURL](pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-5.2.4-and-5.2.5-php-curl.md) + * [disable\_functions bypass - PHP safe\_mode bypass via proc\_open\(\) and custom environment Exploit](pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-safe_mode-bypass-via-proc_open-and-custom-environment-exploit.md) + * [disable\_functions bypass - PHP Perl Extension Safe\_mode Bypass Exploit](pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-perl-extension-safe_mode-bypass-exploit.md) + * [disable\_functions bypass - PHP 5.2.3 - Win32std ext Protections Bypass](pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-5.2.3-win32std-ext-protections-bypass.md) + * [disable\_functions bypass - PHP 5.2 - FOpen Exploit](pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-5.2-fopen-exploit.md) + * [disable\_functions bypass - via mem](pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-via-mem.md) + * [disable\_functions bypass - mod\_cgi](pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-mod_cgi.md) + * [disable\_functions bypass - PHP 4 >= 4.2.0, PHP 5 pcntl\_exec](pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-4-greater-than-4.2.0-php-5-pcntl_exec.md) * [Python](pentesting/pentesting-web/python.md) * [SpEL - Spring Expression Language](pentesting/pentesting-web/spel-spring-expression-language.md) * [Tomcat](pentesting/pentesting-web/tomcat.md) diff --git a/pentesting/pentesting-web/php-tricks-esp/README.md b/pentesting/pentesting-web/php-tricks-esp/README.md index 27d9305fb..31c9d8e4c 100644 --- a/pentesting/pentesting-web/php-tricks-esp/README.md +++ b/pentesting/pentesting-web/php-tricks-esp/README.md @@ -133,7 +133,7 @@ When you have the **usernames** of teh users of the machine. Check the address: \`ls\`; shell\_exec\("ls"\);** -[Check this for more useful PHP functions](php-useful-functions/) +[Check this for more useful PHP functions](php-useful-functions-disable_functions-open_basedir-bypass/) ### **Code execution using** **preg\_replace\(\)** diff --git a/pentesting/pentesting-web/php-tricks-esp/php-useful-functions/README.md b/pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/README.md similarity index 99% rename from pentesting/pentesting-web/php-tricks-esp/php-useful-functions/README.md rename to pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/README.md index 6fe02fce1..597f743fc 100644 --- a/pentesting/pentesting-web/php-tricks-esp/php-useful-functions/README.md +++ b/pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/README.md @@ -1,4 +1,4 @@ -# PHP - Useful Functions & disable\_functiosns/open\_basedir bypass +# PHP - Useful Functions & disable\_functions/open\_basedir bypass ## PHP Command & Code Execution diff --git a/pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-bypass-dl-function.md b/pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-dl-function.md similarity index 100% rename from pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-bypass-dl-function.md rename to pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-dl-function.md diff --git a/pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-bypass-imagick-less-than-3.3.0-php-greater-than-5.4-exploit.md b/pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-imagick-less-than-3.3.0-php-greater-than-5.4-exploit.md similarity index 100% rename from pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-bypass-imagick-less-than-3.3.0-php-greater-than-5.4-exploit.md rename to pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-imagick-less-than-3.3.0-php-greater-than-5.4-exploit.md diff --git a/pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-bypass-mod_cgi.md b/pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-mod_cgi.md similarity index 100% rename from pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-bypass-mod_cgi.md rename to pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-mod_cgi.md diff --git a/pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-bypass-php-4-greater-than-4.2.0-php-5-pcntl_exec.md b/pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-4-greater-than-4.2.0-php-5-pcntl_exec.md similarity index 100% rename from pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-bypass-php-4-greater-than-4.2.0-php-5-pcntl_exec.md rename to pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-4-greater-than-4.2.0-php-5-pcntl_exec.md diff --git a/pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-bypass-php-5.2-fopen-exploit.md b/pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-5.2-fopen-exploit.md similarity index 100% rename from pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-bypass-php-5.2-fopen-exploit.md rename to pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-5.2-fopen-exploit.md diff --git a/pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-bypass-php-5.2.3-win32std-ext-protections-bypass.md b/pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-5.2.3-win32std-ext-protections-bypass.md similarity index 100% rename from pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-bypass-php-5.2.3-win32std-ext-protections-bypass.md rename to pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-5.2.3-win32std-ext-protections-bypass.md diff --git a/pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-bypass-php-5.2.4-and-5.2.5-php-curl.md b/pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-5.2.4-and-5.2.5-php-curl.md similarity index 100% rename from pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-bypass-php-5.2.4-and-5.2.5-php-curl.md rename to pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-5.2.4-and-5.2.5-php-curl.md diff --git a/pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-bypass-php-7.0-7.4-nix-only.md b/pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-7.0-7.4-nix-only.md similarity index 100% rename from pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-bypass-php-7.0-7.4-nix-only.md rename to pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-7.0-7.4-nix-only.md diff --git a/pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-bypass-php-fpm-fastcgi.md b/pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-fpm-fastcgi.md similarity index 100% rename from pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-bypass-php-fpm-fastcgi.md rename to pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-fpm-fastcgi.md diff --git a/pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-bypass-php-less-than-5.2.9-on-windows.md b/pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-less-than-5.2.9-on-windows.md similarity index 100% rename from pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-bypass-php-less-than-5.2.9-on-windows.md rename to pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-less-than-5.2.9-on-windows.md diff --git a/pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-bypass-php-perl-extension-safe_mode-bypass-exploit.md b/pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-perl-extension-safe_mode-bypass-exploit.md similarity index 100% rename from pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-bypass-php-perl-extension-safe_mode-bypass-exploit.md rename to pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-perl-extension-safe_mode-bypass-exploit.md diff --git a/pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-bypass-php-safe_mode-bypass-via-proc_open-and-custom-environment-exploit.md b/pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-safe_mode-bypass-via-proc_open-and-custom-environment-exploit.md similarity index 100% rename from pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-bypass-php-safe_mode-bypass-via-proc_open-and-custom-environment-exploit.md rename to pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-safe_mode-bypass-via-proc_open-and-custom-environment-exploit.md diff --git a/pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-bypass-via-mem.md b/pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-via-mem.md similarity index 100% rename from pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-bypass-via-mem.md rename to pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-via-mem.md diff --git a/pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-php-5.2.4-ioncube-extension-exploit.md b/pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-php-5.2.4-ioncube-extension-exploit.md similarity index 100% rename from pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-php-5.2.4-ioncube-extension-exploit.md rename to pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-php-5.2.4-ioncube-extension-exploit.md diff --git a/pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-php-5.x-shellshock-exploit.md b/pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-php-5.x-shellshock-exploit.md similarity index 100% rename from pentesting/pentesting-web/php-tricks-esp/php-useful-functions/disable_functions-php-5.x-shellshock-exploit.md rename to pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-php-5.x-shellshock-exploit.md