<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>PHP on WE ARE THE BUG</title><link>https://wearethebug.dev/tags/php/</link><description>Recent content on WE ARE THE BUG</description><generator>Tradecraft</generator><language>en-us</language><lastBuildDate>Fri, 20 Sep 2024 00:00:00 +0000</lastBuildDate><atom:link href="https://wearethebug.dev/tags/php/index.xml" rel="self" type="application/rss+xml"/><item><title>VULNLAB: Down</title><link>https://wearethebug.dev/posts/vl-down/</link><pubDate>Fri, 20 Sep 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-down/</guid><description>Down is an easy-rated Linux machine that involves exploiting an arbitrary file read by bypassing a protocol-based filter to discover the source code of the running PHP web app, eventually, a remote code execution to gain an initial foothold. The attacker finds a readable pswm encrypted file in the user's home directory. The pwsm uses Python's cryptocode module and a master password to encrypt and decrypt the data. The attacker is supposed to write a small script to decrypt the blob and compromise the user. The compromised user is a member of the sudo group, allowing the user to escalate and obtain root access.</description></item><item><title>VULNLAB: Dump</title><link>https://wearethebug.dev/posts/vl-dump/</link><pubDate>Mon, 13 Mar 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-dump/</guid><description>Dump is a Hard-rated Linux machine featuring a custom PHP web application that allows the creation of packet captures as well as upload and download functionality of pcap files. The machine demonstrates command argument injection through file naming to obtain initial remote code execution as www-data. Enumeration of the system reveals a sudo rule with tcpdump that can be abused for arbitrary file writes to the system and bypassing AppArmor security policy restrictions. With arbitrary file writes players can write malicious Message of The Day configurations that execute as root during system login.</description></item><item><title>VULNLAB: Zero</title><link>https://wearethebug.dev/posts/vl-zero/</link><pubDate>Fri, 25 Feb 2022 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-zero/</guid><description>Zero is an Insane difficulty Linux machine that features a web application that allows for the creation of credentials to be used on an SFTP server where users can create their own HTML pages. This service is exploitable by uploading a malicious .htaccess file to gain arbitrary file read access to the web servers' asset files. By viewing the source code of these files players will find hard coded credentials that allow for access to the target over SSH. The Apache server configuration is periodically managed by a cronjob that checks the integrity of the Apache configurations and can be abused by satisfying the conditions of the cronjob task to include a malicious line into the restored configuration to leak the contents of files owned by root.</description></item></channel></rss>