turksec12 Posted September 2, 2016 Report Posted September 2, 2016 bypassed ? Disable functions : symlink, shell_exec, passthru, error_log, ini_alter, dl, pfsockopen, openlog, syslog, readlink, symlink, link, leak, popen, escapeshellcmd, proc_close, proc_get_status, proc_nice, proc_open, proc_terminate, escapeshellarg, pcntl_exec,phpmail,mail,hopenbasedir,system,dl,passthru,cat,exec, popen, proc_close, proc_get_status,proc_nice,proc_open, escapeshellcmd, show_source,posix_mkfifo,mysql_list_dbs,get_current_user, getmyuid, pconnect, link, pcntl_exec,ini_alter,leak,apache_child_terminate,posix_kill,posix_setpgid,posix_setsid,posix_setuid,posix_getpwuid,proc_terminate,syslog,fpassthru,stream_select,socket_select,socket_create,socket_create_listen,socket_create_pair,socket_listen,socket_accept,socket_bind,pcntl_fork,pcntl_signal,pcntl_waitpid,pcntl_wexitstatus,pcntl_wifexited,pcntl_wifsignaled,pcntl_wifstopped,pcntl_wstopsig,pcntl_wtermsig,openlog,apache_get_modules,apache_get_version,apache_getenv,apache_note,apache_setenv,virtual,user_dir,ini_restore,cat,pl,cut,restore_ini,f_open,passthru,proc_close,proc_nice,escapeshellcmd,show_source,mysql_list,getmyuid,link,posix_kill,posix_setuid,stream_select,socket_create_pair,socket_bind,foreach,pcntl_wexitstatus,pcntl_wtermsig,apache_get_modules,apache_get_version,password,c99,r57,wget,get,cat,ls,ln,tac,find,.pl,/var,/home,/usr,telnet.req,mass.pl,zoneh.pl Uname -a: Linux fr1.fiberdns.net 3.10.0-327.22.2.el7.x86_64 #1 SMP Thu Jun 23 17:05:11 UTC 2016 x86_64 Quote