A PHP web-hacking challenge demonstrated how attacker-controlled input written into a generated PHP configuration file can become executable code. The application removed double quotes, single quotes, and semicolons from a data parameter, but then embedded the value in a double-quoted PHP string; PHP variable-interpolation syntax could still invoke attacker-controlled functions when the generated file was requested.
The technique enabled PHP code execution and inspection of runtime configuration. A broad disable_functions policy did not prevent disclosure of a protected key.php file because gzfile remained available, illustrating that partial PHP function blacklists and dynamically generated executable configuration files do not provide reliable isolation.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
The demonstrated exploit used phpinfo() to inspect restrictions, then called gzfile—absent from the disable_functions list—to read ../key.php and obtain the protected challenge key.
A PHP web-hacking challenge accepted attacker-controlled GET parameters and wrote the data value into a generated PHP configuration file. Despite filtering quotes and semicolons, PHP double-quoted string interpolation allowed attackers to execute PHP code when the generated file was accessed.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
kingkk.com
Open sourceicheernoom.blogspot.tw
Open sourceblog.orange.tw
Open sourcewonderkun.cc
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.