baidu / baidu/openrasp

php代码执行绕过

Open
#397 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
C++
Stars
3k
Forks
622
PR merge metrics
No merged PRs in 30d

Description

php eval绕过拦截执行代码

PHP Version 7.2.33

一句话正常被拦截,但是header一句话就可以绕过拦截
``

Status | Protected
-- | --
Version | 1.3.7
Build Time | 2022-01-28 17:56:21
Commit Id | a0634d6
V8 Version | 7.8

Contributor guide

Open the contributing guide

Research direction

Reproduce the report with PHP 7.2.33, OpenRASP 1.3.7, and the eval($_SERVER['HTTP_ACCEPT']) payload sent through the HTTP_ACCEPT header. Start at the eval interception path and verify that the request is blocked while normal requests remain unaffected; the issue names no source files or tests.

Written by the indexing model from the issue text.

Assessment

Tech stack
php
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.