OSWE GUIDE | "Build it and break it (PHP Blog)" Part 1 | Building the PHP Web App!

Опубликовано: 22 Октябрь 2024
на канале: SecAura
2,528
63

In part 1 of my OSWE Prep "Build it and break it (PHP Blog)" series, I go through the development side of a PHP web app, building it, explaining the underlying code and demonstrating its basic functionality, before exploting in in part 2!
I have built this web series to go through the whole steps of creating a web application and exploiting it from 0 to RCE!

Part 0 -    • OSWE Review + OSWE "Build and break i...  
Part 1 -    • OSWE GUIDE | "Build it and break it (...  
Part 2 -    • OSWE GUIDE | "Build it and break it (...  
Part 3 -    • OSWE GUIDE | "Build it and break it (...  

⏱️Timestamps:
➡️ 00:00 - Intro
➡️ 05:00 - Building the application (PHP)
➡️ 05:30 - Adding database PHP connection functionality / explanation
➡️ 06:45 - Adding comment insert into database functionality (index.php)
➡️ 09:30 - Adding comment listing functionality
➡️ 12:10 - Bulding the admin functionality (admin.php)
➡️ 12:40 - Explaining the localhost admin checks in place (isAdmin.php)
➡️ 14:00 - Demonstrating the isAdmin.php checks from a none localhost system
➡️ 14:50 - Explaining/adding the admin comment panel backend
➡️ 17:20 - Showing the coherance of the code
➡️ 17:35 - Explaining the code behind upload.php
➡️ 18:00 - Explaining the file upload XML parser / Hidden application code
➡️ 20:00 - Summary of application and relevance to OSWE course exam
➡️ 20:50 - Talk of what we are going to next to attack



⭐️Link to web app code:
🔗 https://github.com/SecAuraYT/OSWE

For more Cyber security/hacking based content, check out the rest of my channel - covering SQL injection, server side template injection, remote code execution/injection(rce), linux/windows privilege escalation, wireshark, CVE's, hackthebox, scripting - web application security testing automation etc. :)