diff --git a/Payloads/PHPInfo.zip b/Payloads/PHPInfo.zip new file mode 100644 index 00000000..eea07d7c Binary files /dev/null and b/Payloads/PHPInfo.zip differ diff --git a/Payloads/PHPInfo/make-aio.sh b/Payloads/PHPInfo/make-aio.sh deleted file mode 100755 index 916c604d..00000000 --- a/Payloads/PHPInfo/make-aio.sh +++ /dev/null @@ -1,5 +0,0 @@ -#!/bin/sh -zip phpinfo-aio.zip phpinfo*.{p*,txt,jp*g,gif} - -tar -cvf phpinfo-aio.tar phpinfo*.{p*,txt,jp*g,gif} - diff --git a/Payloads/PHPInfo/phpinfo-aio.tar b/Payloads/PHPInfo/phpinfo-aio.tar deleted file mode 100644 index 10898d55..00000000 Binary files a/Payloads/PHPInfo/phpinfo-aio.tar and /dev/null differ diff --git a/Payloads/PHPInfo/phpinfo-aio.zip b/Payloads/PHPInfo/phpinfo-aio.zip deleted file mode 100644 index 151f5c87..00000000 Binary files a/Payloads/PHPInfo/phpinfo-aio.zip and /dev/null differ diff --git a/Payloads/PHPInfo/phpinfo-metadata.gif b/Payloads/PHPInfo/phpinfo-metadata.gif deleted file mode 100644 index 67f5d453..00000000 Binary files a/Payloads/PHPInfo/phpinfo-metadata.gif and /dev/null differ diff --git a/Payloads/PHPInfo/phpinfo-metadata.jpg b/Payloads/PHPInfo/phpinfo-metadata.jpg deleted file mode 100644 index 580cf6f1..00000000 Binary files a/Payloads/PHPInfo/phpinfo-metadata.jpg and /dev/null differ diff --git a/Payloads/PHPInfo/phpinfo-shortsyntax.php b/Payloads/PHPInfo/phpinfo-shortsyntax.php deleted file mode 100644 index 52801137..00000000 --- a/Payloads/PHPInfo/phpinfo-shortsyntax.php +++ /dev/null @@ -1,3 +0,0 @@ -//tested on 7.2 -// even with short_open_tag=0 - diff --git "a/Payloads/PHPInfo/phpinfo.\"\"gif" "b/Payloads/PHPInfo/phpinfo.\"\"gif" deleted file mode 100644 index fc4c7547..00000000 --- "a/Payloads/PHPInfo/phpinfo.\"\"gif" +++ /dev/null @@ -1,2 +0,0 @@ -GIF89a1 - diff --git "a/Payloads/PHPInfo/phpinfo.\"gif" "b/Payloads/PHPInfo/phpinfo.\"gif" deleted file mode 100644 index fc4c7547..00000000 --- "a/Payloads/PHPInfo/phpinfo.\"gif" +++ /dev/null @@ -1,2 +0,0 @@ -GIF89a1 - diff --git a/Payloads/PHPInfo/phpinfo.''gif b/Payloads/PHPInfo/phpinfo.''gif deleted file mode 100644 index fc4c7547..00000000 --- a/Payloads/PHPInfo/phpinfo.''gif +++ /dev/null @@ -1,2 +0,0 @@ -GIF89a1 - diff --git a/Payloads/PHPInfo/phpinfo.'gif b/Payloads/PHPInfo/phpinfo.'gif deleted file mode 100644 index fc4c7547..00000000 --- a/Payloads/PHPInfo/phpinfo.'gif +++ /dev/null @@ -1,2 +0,0 @@ -GIF89a1 - diff --git a/Payloads/PHPInfo/phpinfo.jpg.php b/Payloads/PHPInfo/phpinfo.jpg.php deleted file mode 100644 index 147cebcd..00000000 --- a/Payloads/PHPInfo/phpinfo.jpg.php +++ /dev/null @@ -1 +0,0 @@ - diff --git a/Payloads/PHPInfo/phpinfo.php b/Payloads/PHPInfo/phpinfo.php deleted file mode 100644 index 147cebcd..00000000 --- a/Payloads/PHPInfo/phpinfo.php +++ /dev/null @@ -1 +0,0 @@ - diff --git a/Payloads/PHPInfo/phpinfo.php-1.gif b/Payloads/PHPInfo/phpinfo.php-1.gif deleted file mode 100644 index fc4c7547..00000000 --- a/Payloads/PHPInfo/phpinfo.php-1.gif +++ /dev/null @@ -1,2 +0,0 @@ -GIF89a1 - diff --git a/Payloads/PHPInfo/phpinfo.php-2.gif b/Payloads/PHPInfo/phpinfo.php-2.gif deleted file mode 100644 index 4872e8d7..00000000 --- a/Payloads/PHPInfo/phpinfo.php-2.gif +++ /dev/null @@ -1 +0,0 @@ -GIF89a1 diff --git "a/Payloads/PHPInfo/phpinfo.php.\"\"gif" "b/Payloads/PHPInfo/phpinfo.php.\"\"gif" deleted file mode 100644 index fc4c7547..00000000 --- "a/Payloads/PHPInfo/phpinfo.php.\"\"gif" +++ /dev/null @@ -1,2 +0,0 @@ -GIF89a1 - diff --git "a/Payloads/PHPInfo/phpinfo.php.\"gif" "b/Payloads/PHPInfo/phpinfo.php.\"gif" deleted file mode 100644 index fc4c7547..00000000 --- "a/Payloads/PHPInfo/phpinfo.php.\"gif" +++ /dev/null @@ -1,2 +0,0 @@ -GIF89a1 - diff --git a/Payloads/PHPInfo/phpinfo.php.''gif b/Payloads/PHPInfo/phpinfo.php.''gif deleted file mode 100644 index fc4c7547..00000000 --- a/Payloads/PHPInfo/phpinfo.php.''gif +++ /dev/null @@ -1,2 +0,0 @@ -GIF89a1 - diff --git a/Payloads/PHPInfo/phpinfo.php.'gif b/Payloads/PHPInfo/phpinfo.php.'gif deleted file mode 100644 index fc4c7547..00000000 --- a/Payloads/PHPInfo/phpinfo.php.'gif +++ /dev/null @@ -1,2 +0,0 @@ -GIF89a1 - diff --git a/Payloads/PHPInfo/phpinfo.php3 b/Payloads/PHPInfo/phpinfo.php3 deleted file mode 100644 index 147cebcd..00000000 --- a/Payloads/PHPInfo/phpinfo.php3 +++ /dev/null @@ -1 +0,0 @@ - diff --git a/Payloads/PHPInfo/phpinfo.php4 b/Payloads/PHPInfo/phpinfo.php4 deleted file mode 100644 index 147cebcd..00000000 --- a/Payloads/PHPInfo/phpinfo.php4 +++ /dev/null @@ -1 +0,0 @@ - diff --git a/Payloads/PHPInfo/phpinfo.php5 b/Payloads/PHPInfo/phpinfo.php5 deleted file mode 100644 index 147cebcd..00000000 --- a/Payloads/PHPInfo/phpinfo.php5 +++ /dev/null @@ -1 +0,0 @@ - diff --git a/Payloads/PHPInfo/phpinfo.php7 b/Payloads/PHPInfo/phpinfo.php7 deleted file mode 100644 index 147cebcd..00000000 --- a/Payloads/PHPInfo/phpinfo.php7 +++ /dev/null @@ -1 +0,0 @@ - diff --git a/Payloads/PHPInfo/phpinfo.php;.txt b/Payloads/PHPInfo/phpinfo.php;.txt deleted file mode 100644 index 147cebcd..00000000 --- a/Payloads/PHPInfo/phpinfo.php;.txt +++ /dev/null @@ -1 +0,0 @@ - diff --git a/Payloads/PHPInfo/phpinfo.phpt b/Payloads/PHPInfo/phpinfo.phpt deleted file mode 100644 index 147cebcd..00000000 --- a/Payloads/PHPInfo/phpinfo.phpt +++ /dev/null @@ -1 +0,0 @@ - diff --git a/Payloads/PHPInfo/phpinfo.pht b/Payloads/PHPInfo/phpinfo.pht deleted file mode 100644 index 147cebcd..00000000 --- a/Payloads/PHPInfo/phpinfo.pht +++ /dev/null @@ -1 +0,0 @@ - diff --git a/Payloads/PHPInfo/phpinfo.phtml b/Payloads/PHPInfo/phpinfo.phtml deleted file mode 100644 index 147cebcd..00000000 --- a/Payloads/PHPInfo/phpinfo.phtml +++ /dev/null @@ -1 +0,0 @@ - diff --git a/Payloads/PHPInfo/phpinfo.txt b/Payloads/PHPInfo/phpinfo.txt deleted file mode 100644 index 147cebcd..00000000 --- a/Payloads/PHPInfo/phpinfo.txt +++ /dev/null @@ -1 +0,0 @@ - diff --git a/Payloads/README.md b/Payloads/README.md index 121453de..9e29f748 100644 --- a/Payloads/README.md +++ b/Payloads/README.md @@ -44,4 +44,39 @@ IE9: http://0me.me/demo/xss/xssproject.swf?js=w=window.open(‘invalidfileinvali ## POC_img_phpinfo File -Outlined here: https://www.secgeek.net/bookfresh-vulnerability/ \ No newline at end of file +Outlined here: https://www.secgeek.net/bookfresh-vulnerability/ + + +## PHPInfo.zip + +This zip file containes files with filenames for bypassing blacklists and accessing `phpinfo.php`: + +- ` make-aio.sh` +- ` phpinfo-aio.tar` +- ` phpinfo-aio.zip` +- `'phpinfo.""gif'` +- `'phpinfo."gif'` +- `"phpinfo.''gif"` +- `"phpinfo.'gif"` +- ` phpinfo.jpg.php` +- ` phpinfo-metadata.gif` +- ` phpinfo-metadata.jpg` +- ` phpinfo.php` +- ` phpinfo.php-1.gif` +- ` phpinfo.php-2.gif` +- ` phpinfo.php3` +- ` phpinfo.php4` +- ` phpinfo.php5` +- ` phpinfo.php7` +- `'phpinfo.php.""gif'` +- `'phpinfo.php."gif'` +- `"phpinfo.php.''gif"` +- `"phpinfo.php.'gif"` +- ` phpinfo.phpt` +- `'phpinfo.php;.txt'` +- ` phpinfo.pht` +- ` phpinfo.phtml` +- ` phpinfo-shortsyntax.php` +- ` phpinfo.txt` + +It's impossible to unzip this file on Windows, due to their arbitrary filename restrictions. It's possible to unzip it in WSL though.