metasploit-framework
https://github.com/rapid7/metasploit-framework
Ruby
Metasploit Framework
MetasploitModule#upload_php_backdoor
Uploads the PHP backdoor onto the target machine. The reason of using a PHP backdoor to upload is because our SQL injection is in a GET method, and Apache has a max length of 8190 bytes, which is bad for some built-in or custom payloads.
Edit
git clone [email protected]:rapid7/metasploit-framework.git
cd metasploit-framework
open modules/exploits/multi/http/sonicwall_scrutinizer_methoddetail_sqli.rb
Contribute
# Make a new branchgit checkout -b -your-name--update-docs-MetasploitModule-upload_php_backdoor-for-pr
# Commit to gitgit add modules/exploits/multi/http/sonicwall_scrutinizer_methoddetail_sqli.rbgit commit -m "better docs for MetasploitModule#upload_php_backdoor"
# Open pull requestgem install hub # on a mac you can `brew install hub`
hub fork
git push <your name> -your-name--update-docs-MetasploitModule-upload_php_backdoor-for-pr
hub pull-request
# Celebrate!