Laravel CVE-2018-15133 - 資安

Ina avatar
By Ina
at 2018-12-13T12:47

Table of Contents

====================================================================
== Subject:
Laravel RCE with APP_KEY leaked

== CVE ID#:
CVE-2018-15133

== Versions:
Laravel 5.6.29 application on PHP 7.2.10

== Summary:
Laravel CVE-2018-15133 https://github.com/kozmic/laravel-poc-CVE-2018-15133


This repository contains a simple Laravel 5.6.29 application on PHP 7.2.10
with one basic noop route added in routes/web.php (see Dockerfile) and Proof
of Concept exploit (cve-2018-15133.php) for CVE-2018-15133 that should
successfully exploit the Laravel application and execute uname -a on the
target system.
====================================================================

看起來有一些人晚上又不睡覺了

--
Tags: 資安

All Comments

Jacky avatar
By Jacky
at 2018-12-18T03:00
哈哈

一題ROP

George avatar
By George
at 2018-12-09T18:04
最近再看inndy的rop2可是看了writeup還是不懂為何這樣寫 題目是rop2 http://www.carlstar.club/2018/10/24/hackme.inndy.tw-pwn/ 關鍵payload是這樣 payload = fit({0xc + 0x4:[p32(addr_sys ...

學校網路被鎖

Barb Cronin avatar
By Barb Cronin
at 2018-12-04T22:42
是這樣的 有不知名人事連我們實驗室的網路 導致被網管人員鎖起來了 有辦法查到誰是兇手嗎 - ...

萬豪酒店坦承遇駭 5億客戶個資外洩含信

James avatar
By James
at 2018-12-01T02:17
萬豪酒店坦承遇駭 5億客戶個資外洩含信用卡號 https://tw.news.appledaily.com/international/realtime/20181130/1476335/ 出版時間:2018/11/30 20:19 路透 https://i.imgur.com/CnZSB3H.jpg < ...

萬豪酒店坦承遇駭 5億客戶個資外洩含信

Mason avatar
By Mason
at 2018-12-01T02:17
萬豪酒店坦承遇駭 5億客戶個資外洩含信用卡號 https://tw.news.appledaily.com/international/realtime/20181130/1476335/ 出版時間:2018/11/30 20:19 路透 https://i.imgur.com/CnZSB3H.jpg ...

[email protected] exploited

Andrew avatar
By Andrew
at 2018-11-27T10:07
https://github.com/dominictarr/event-stream/issues/116 Issue Title 就寫了另人有興致的 I donand#39;t know what to say. 按照 issue 描述的說法 當你同時安裝 flatmap-streamat0.1.1 ...