Top 10 winner
It's A PHP Unserialization Vulnerability Jim But Not As We Know It
BSidesMCR 2018: It's A PHP Unserialization Vulnerability Jim, But Not As We Know It by Sam Thomas
Any PHP file operation on an attacker-controlled path beginning phar:// unserializes the archive's metadata, so file-existence checks, XXE and SSRF bugs become object injection. A Phar can be disguised as a valid JPEG to survive upload checks, and POP gadget chains then give code execution, shown against Typo3, WordPress and TCPDF via Contao.
Record
- Document
- BSidesMCR 2018: It's A PHP Unserialization Vulnerability Jim, But Not As We Know It by Sam Thomas
- Researcher
- Sam Thomas
- Published by
- Secarma Labs
- Date
- Format
- Recording
- Topic
- Server
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Sam Thomas, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .