bWAPP PHP Code Injection

preview_player
Показать описание
php Code Injection is the general term for attack types which consist of injecting code that is then interpreted/executed by the application. This type of attack exploits poor handling of untrusted data.
Attacker use this script phpinfo()
Рекомендации по теме
Комментарии
Автор

Nice video. I would like to add that you can also use this point for Remote Code Execution. example: phpi.php?message=system("ls -all") or
phpi.php?message=system("cat /etc/passwd") PS. I subscribed to you.

jimcolabuchanan