Skip to content

Instantly share code, notes, and snippets.

@jakeajames
jakeajames / poc.c
Last active May 1, 2023 19:58
CVE-2021-30955 PoC
#include <stdlib.h>
#include <stdio.h>
#include <pthread/pthread.h>
#include <mach/mach.h>
struct ool_msg {
mach_msg_header_t hdr;
mach_msg_body_t body;
mach_msg_ool_ports_descriptor_t ool_ports[];
};
@PinkDraconian
PinkDraconian / cli.php
Created February 28, 2022 12:57
Can you spot the vulnerability?
<?php
if (!isset($_SERVER['argc']) || $_SERVER['argc'] < 1) {
die("Usage: cli <action> <options>");
}
$argc = $_SERVER['argc'];
$argv = $_SERVER['argv'];
switch ($argv[1]) {
case "ls":
echo "Listing directory";
https://uat-www.oppo.com
https://uat-www.oppo.com
https://after-sales.oppo.com
https://after-sales.oppo.com
https://warranty.oppo.com
https://warranty.oppo.com
https://pop.oppo.com
https://go.oppo.com/js/chunk-2d216b6c.03c27c1b.js
https://store-statics-id.oppo.com
https://go.oppo.com/js/chunk-77a3b9bb.50500fbd.js