Skip to content

disabled_functions=mail,putenv ;) #2

@defensahacker

Description

@defensahacker

Good job and nice technique, but in a very restricted environment where mail() and putenv() are also in disabled_functions it may not work.

I am doing some further research if there is any function inside get_defined_functions() that also executes an execve() behind the scenes... or another method like transform chankro.so into ftp.so to trojanize ftp php functions if putenv(LD_PRELOAD) is available and is called before ftp_connect()...

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions