Giter Club home page Giter Club logo

php-audit-labs's Introduction

PHP-Audit-Labs

language PHP-Code-Review license

大家好,我们是红日安全-代码审计小组。此项目是关于代码审计的系列文章分享,还包含一个CTF靶场供大家练习,我们给这个项目起了一个名字叫 PHP-Audit-Labs ,希望对想要学习代码审计的朋友们有所帮助。如果你愿意加入我们,一起完善这个项目,欢迎通过邮件形式([email protected])联系我们。

Part1

Part1 部分属于项目 第一阶段 的内容,本阶段的内容题目素材均来自 PHP SECURITY CALENDAR 2017 。对于每一道题目,我们均给出对应的分析,并结合实际CMS进行解说。在文章的最后,我们还会留一道CTF题目,供大家练习,文章内容如下:

Part2

Part2 部分属于项目 第二阶段 的内容,本阶段的内容主要分析 PHP 主流框架中存在的漏洞,文章内容如下:

ThinkPHP5

PHP-Audit-Labs题解

PHP-Audit-Labs CTF-Docker环境

项目维护

免责说明

请勿用于非法的用途,否则造成的严重后果与本项目无关

转载

转载请注明来自

https://github.com/hongriSec/PHP-Audit-Labs/

投搞

欢迎大家投搞

[email protected]

php-audit-labs's People

Contributors

hongrisec avatar mochazz avatar redbull2015 avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

php-audit-labs's Issues

day1查flag表存在flag列

过滤了or,就是过滤了information_schema,我用schema_auto_increment_columns绕过了information_schema,查出了当前库下存在flag表,但flag表下存在flag列是怎么查出来的我不清楚,望解答

发现宝藏!!!

这个项目真的做得好好!!!七月火...他真的,我哭死,太好了
好希望能继续做同类项目

Image not found

in this docker file:

FROM zhhhy/lampp


ADD ./day1/ /var/www/html
RUN ls /var/www/html/
RUN chmod 777 /var/www/html/run.sh
CMD ["sh","/var/www/html/run.sh"]
EXPOSE 80

use zhhhy/lampp as a default images, however, it's not found now, mayble it's owner has deleted it.

docker build -t day1 . Repo not found

docker build -t day1 .
Emulate Docker CLI using podman. Create /etc/containers/nodocker to quiet msg.
STEP 1/6: FROM zhhhy/lamp
✔ registry.access.redhat.com/zhhhy/lamp:latest
Trying to pull registry.access.redhat.com/zhhhy/lamp:latest...
Error: creating build container: initializing source docker://registry.access.redhat.com/zhhhy/lamp:latest: reading manifest latest in registry.access.redhat.com/zhhhy/lamp: name unknown: Repo not found

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.