PHP 8.1.0-dev - 'User-Agentt' Remote Code Execution | Manual Exploit | Hindi

preview_player
Показать описание
#PHP #RCE #Exploit

PHP verion 8.1.0-dev was released with a backdoor on March 28th 2021, but the backdoor was quickly discovered and removed. If this version of PHP runs on a server, an attacker can execute arbitrary code by sending the User-Agentt header.

The original code was restored after the issue was discovered, but then tampered with a second time. The breach would have created a backdoor in any websites that ran the compromised version of PHP, enabling hackers to perform remote code execution on the site.

Reference:

Commands Used in Video:
Curl -I url
Got php8.1.0-dev

Searchsploit php 8.1.0
Got useragent rce

Nc -lvnp 1234

Covers:
remote code execution
remote code execution poc
remote code execution vulnerability
remote code execution tutorial
remote code execution in hindi
remote code execution (rce)
laravel remote code execution
arbitrary code execution
remote code execution bug bounty
remote command execution youtube
code execution
remote code execution php
php remote code execution
remote code execution cve
remote code execution attack
remote command execution
Рекомендации по теме
Комментарии
Автор

Bhai step by step batao aur aap Aisa kyo kar rahe ho uska reason bhi batao.main expert nahi hoon bhai

Pokemonunitebyrahul
Автор

Is there any google dork to find this version of sites ?

Bob-hkmx