Home

Awesome

fpmvuln

bash poc scripts to exploit open fpm ports

fpmexfil

Will try to exfiltrate /etc/passwd from target host. Works with many hosts using HHVM exposed on a public interface

fpmrce

Will try to execute PHP code on remote host. Works with most PHP installations exposing fpm on the public port.

background

misc

There were previous, similar exploits for these issues: