FastCGI Pentesting
FastCGI is a binary protocol for interfacing interactive programs with a web server. It uses 9000 port by default.
If the PHP-FPM (FastCGI Process Manager) is running on the target system, we might be able to execute arbitrary command.
Remote Code Execution
We need to create an arbitrary PHP file somewhere. For instance,
Then create a shell script named "".
Now execute the shell script. Of course we have to start a listener in local machine for reverse shell before executing the following command.
Last updated