Breaking PHP’s Garbage Collection and Unserialize 07-25-2016, 07:12 PM
#1
Since I'm too lazy to contribute with actual tutorials, in order to make this a "security" forum again, I'm going to be posting stuff like this every now and then.
This is a really interesting read for anyone who's interested in both OS-level exploitation and web exploitation. This is what was used to hack pornhub and gain RCE. Too bad it fell into the hands of white hats...
https://www.evonide.com/breaking-phps-ga...serialize/
This is a really interesting read for anyone who's interested in both OS-level exploitation and web exploitation. This is what was used to hack pornhub and gain RCE. Too bad it fell into the hands of white hats...
https://www.evonide.com/breaking-phps-ga...serialize/

![[+]](https://sinister.ly/images/modern/collapse_collapsed.png)