Jump to content
YOUR-AD-HERE
HOSTING
TOOLS

Locked LKWA


0x1

Recommended Posts

Lesser Known Web Attack Lab

This is the hidden content, please

Lesser Known Web Attack Lab is for intermediate pentester that can test and practice lesser known web attacks such as Object Injection, XSSI, PHAR Deserialization, variables variable ..etc. Write-ups are welcome. The own walk-through is

This is the hidden content, please

Current Vulns

  • Blind RCE
  • XSSI
  • PHAR Deserialization
  • PHP Object Injection
  • PHP Object Injection via Cookies
  • PHP Object Injection (Object Reference)
  • SSRF
  • Variables variable

 

Installation

Just clone the git with

This is the hidden content, please
and move it to your web server and you are good to go.

  • For XSSI, challenge you need to change Allow Override None to Allow Override ALL in apache2.conf file.
  • For PHAR Deserialization, you need to change phar.readonly = On to phar.readonly = Off in php.ini setting.

Installation - Docker

Just run docker-compose up inside the Docker folder and open the browser on http://localhost:3000.

Download & Source

This is the hidden content, please

 

Edited by 0x1
fix tag hidden
Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.