webProeasy

Десериализатор

bug-makers

Task: PHP web app passes user POST data directly to unserialize(), source contains FileReader class with __destruct() reading files. Solution: craft serialized FileReader object with private filename property set to flag.txt, null bytes required for private property serialization.

$ ls tags/ techniques/
php_insecure_deserializationdestruct_gadgetprivate_property_null_bytes

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups