summaryrefslogtreecommitdiff
path: root/data/samples/artificial
diff options
context:
space:
mode:
authorMathieu Deous2022-05-02 20:18:23 +0200
committerGitHub2022-05-02 20:18:23 +0200
commit48936efa96ae17295be4e0a71be3294f0ec6aef8 (patch)
treef4e69551f1368aa048edf46b7b061600f3668329 /data/samples/artificial
parentbbc738e16f8b637afde58d65196374af98a5e0e2 (diff)
Make application go-install-able and create a docker image
Diffstat (limited to 'data/samples/artificial')
-rw-r--r--data/samples/artificial/bypasses.php7
-rw-r--r--data/samples/artificial/dodgy.php18
-rw-r--r--data/samples/artificial/obfuscated.php8
3 files changed, 33 insertions, 0 deletions
diff --git a/data/samples/artificial/bypasses.php b/data/samples/artificial/bypasses.php
new file mode 100644
index 0000000..9d849a4
--- /dev/null
+++ b/data/samples/artificial/bypasses.php
@@ -0,0 +1,7 @@
1<?php
2
3// https://rstforums.com/forum/topic/98500-php-malware-finder/?do=findComment&comment=615687
4print_r(call_user_func_array($_POST['functie'], array($_POST['argv'])));
5
6// https://github.com/nbs-system/php-malware-finder/commit/47d86bf92eb15fe65dd4efbc04d0004856e88ddd#commitcomment-16355734
7print_r($_POST['funct']($_POST['argv']));
diff --git a/data/samples/artificial/dodgy.php b/data/samples/artificial/dodgy.php
new file mode 100644
index 0000000..e127588
--- /dev/null
+++ b/data/samples/artificial/dodgy.php
@@ -0,0 +1,18 @@
1<?php
2
3curl_init ( "file:///etc/parla");
4curl_setopt($ch, CURLOPT_URL, "file:file:////etc/passwd");
5set_magic_quotes_runtime ( 0);
6eval(base64_decode($_GET['lol']));
7$a= "SetHandler application/x-httpd-php";
8$b = "IIS://localhost/w3svc";
9include ( 'lol.png');
10ini_get ( 'disable_functions');
11ini_set("disable_functions", "");
12ini_restore("allow_url_include");
13preg_replace ("/*/e");
14$c = "env x='() { :;}; echo vulnerable' bash -c 'echo this is a test'";
15fsockopen ( 'udp://');
16call_user_func('LOL');
17$d = "<!--#exec cmd=";
18$c = "AddType application/x-httpd-php .htaccess"
diff --git a/data/samples/artificial/obfuscated.php b/data/samples/artificial/obfuscated.php
new file mode 100644
index 0000000..fc66be8
--- /dev/null
+++ b/data/samples/artificial/obfuscated.php
@@ -0,0 +1,8 @@
1<?php@eval($_GET['p'])
2<?php assert ( $_GET['p']
3)
4$func="test";$b374k=$func('$x', 'ev'.'al')
5$b=$W('',$S);$b();
6;$pouet($pif,$paf);
7${$pouet}
8'pouet'.'pif' . 'pouet' . "lol" ."kwainkwain"