PHP phar://

Bookmarked!

This exercise covers how the PHP phar:// handler can be used to gain code execution using PHP unserialize.

PRO Medium < 1 Hr. 360 Brown Badge
Course

In this lab, you will learn how to exploit PHP phar deserialization vulnerabilities to gain code execution. You will explore PHP handlers like <code>file://</code> and <code>phar://</code>, and understand how to leak source code and use it to craft a malicious PHP archive.

Skills covered
Injection Authentication Operating System Network
Included with PRO
Full course content 1 video Common mistakes

Ready to practice?

Get access to this lab and 600+ hands-on exercises with a PRO subscription.