Iconv, set the charset to RCE: in the first blog post of this series, @cfreal_ will show a new exploitation vector to get RCE in PHP from a file read primitive, using a bug in iconv() (CVE-2024-2961) ambionics.io/blog/iconv-cve-…

May 27, 2024 Β· 8:48 AM UTC

3
121
296
54,739
Sort replies: Relevant Recent Liked
Replying to @ambionics @cfreal_
πŸ‘πŸ‘πŸ‘πŸ‘πŸ‘πŸ‘πŸ‘πŸ”₯
1
1
4
1,169
Replying to @ambionics @cfreal_
Loved the article! Very professional. Excited for Part 3 – I have a hunch and can’t wait for the release.
1
2
355
Replying to @ambionics @cfreal_
Is it possible to modify php.ini to protect against all attacks that use PHP filters and rarely-used protocols, especially if updating GLIBC is not an option? If so, could you recommend a specific configuration?
1
1
487