0x1 Posted January 11, 2020 Share Posted January 11, 2020 (edited) Lesser Known Web Attack Lab This is the hidden content, please Sign In or Sign Up Lesser Known Web Attack Lab is for intermediate pentester that can test and practice lesser known web attacks such as Object Injection, XSSI, PHAR Deserialization, variables variable ..etc. Write-ups are welcome. The own walk-through is This is the hidden content, please Sign In or Sign Up Current Vulns Blind RCE XSSI PHAR Deserialization PHP Object Injection PHP Object Injection via Cookies PHP Object Injection (Object Reference) SSRF Variables variable Installation Just clone the git with This is the hidden content, please Sign In or Sign Up and move it to your web server and you are good to go. For XSSI, challenge you need to change Allow Override None to Allow Override ALL in apache2.conf file. For PHAR Deserialization, you need to change phar.readonly = On to phar.readonly = Off in php.ini setting. Installation - Docker Just run docker-compose up inside the Docker folder and open the browser on http://localhost:3000. Download & Source This is the hidden content, please Sign In or Sign Up Edited January 11, 2020 by 0x1 fix tag hidden Link to comment Share on other sites More sharing options...
Recommended Posts