├── .gitignore ├── .travis.yml ├── Dockerfile ├── LICENSE ├── README.md ├── README.zh-CN.md ├── artwork ├── dvwa_sentry_index.png └── sentry_detail.png ├── composer.json ├── dvwa ├── Dockerfile ├── README.md ├── README.zh-CN.md ├── config.inc.php ├── entrypoint.php └── prvd.ini ├── entrypoint.php ├── phpunit.xml ├── prvd.ini ├── src ├── Client.php ├── Config.php ├── Entry.php ├── Utils.php ├── filter │ ├── 001-base64_decode.php │ ├── 001-basename.php │ ├── 001-dirname.php │ ├── 001-explode.php │ ├── 001-gzuncompress.php │ ├── 001-hex2bin.php │ ├── 001-html_entity_decode.php │ ├── 001-htmlspecialchars_decode.php │ ├── 001-implode.php │ ├── 001-join.php │ ├── 001-json_decode.php │ ├── 001-ltrim.php │ ├── 001-pathinfo.php │ ├── 001-rawurldecode.php │ ├── 001-rawurlencode.php │ ├── 001-rtrim.php │ ├── 001-sprintf.php │ ├── 001-str_ireplace.php │ ├── 001-str_pad.php │ ├── 001-str_replace.php │ ├── 001-strstr.php │ ├── 001-strtolower.php │ ├── 001-strtoupper.php │ ├── 001-substr.php │ ├── 001-trim.php │ ├── 001-urldecode.php │ ├── 001-urlencode.php │ └── 001-vsprintf.php ├── opcode │ ├── 001-assign_concat.php │ ├── 001-concat.php │ ├── 001-do_fcall.php │ ├── 001-do_fcall_by_name.php │ ├── 001-do_icall.php │ ├── 001-do_ucall.php │ ├── 001-echo.php │ ├── 001-exit.php │ ├── 001-fast_concat.php │ ├── 001-include_or_eval.php │ ├── 001-init_dynamic_call.php │ ├── 001-init_method_call.php │ ├── 001-init_user_call.php │ └── 001-rope_end.php └── sink │ ├── file │ ├── 001-copy.php │ ├── 001-dir.php │ ├── 001-file.php │ ├── 001-file_get_contents.php │ ├── 001-file_put_contents.php │ ├── 001-fopen.php │ ├── 001-glob.php │ ├── 001-highlight_file.php │ ├── 001-link.php │ ├── 001-move_uploaded_file.php │ ├── 001-opendir.php │ ├── 001-readfile.php │ ├── 001-rename.php │ ├── 001-rmdir.php │ ├── 001-scandir.php │ ├── 001-show_source.php │ └── 001-unlink.php │ ├── rce │ ├── 001-exec.php │ ├── 001-passthru.php │ ├── 001-popen.php │ ├── 001-proc_open.php │ ├── 001-shell_exec.php │ ├── 001-system.php │ └── 001-unserialize.php │ ├── sqli │ ├── 001-mysqli.php │ ├── 001-mysqli_init.php │ ├── 001-mysqli_multi_query.php │ ├── 001-mysqli_prepare.php │ ├── 001-mysqli_query.php │ ├── 001-mysqli_real_query.php │ ├── 001-pdo.php │ ├── 001-pg_prepare.php │ ├── 001-pg_query.php │ ├── 001-pg_query_params.php │ ├── 001-pg_send_prepare.php │ ├── 001-pg_send_query.php │ ├── 001-pg_send_query_params.php │ └── 001-sqlite3.php │ ├── ssrf │ ├── 001-curl_exec.php │ ├── 001-fsockopen.php │ └── 001-get_headers.php │ └── xss │ ├── 001-print_r.php │ ├── 001-printf.php │ └── 001-vprintf.php ├── test.sh ├── tests ├── bootstrap.php ├── filter │ ├── 001-base64_decode.php │ ├── 001-basename.php │ ├── 001-dirname.php │ ├── 001-explode.php │ ├── 001-gzuncompress.php │ ├── 001-hex2bin.php │ ├── 001-html_entity_decode.php │ ├── 001-htmlspecialchars_decode.php │ ├── 001-implode.php │ ├── 001-join.php │ ├── 001-json_decode.php │ ├── 001-ltrim.php │ ├── 001-pathinfo.php │ ├── 001-rawurldecode.php │ ├── 001-rawurlencode.php │ ├── 001-rtrim.php │ ├── 001-sprintf.php │ ├── 001-str_ireplace.php │ ├── 001-str_pad.php │ ├── 001-str_replace.php │ ├── 001-strstr.php │ ├── 001-strtolower.php │ ├── 001-strtoupper.php │ ├── 001-substr.php │ ├── 001-trim.php │ ├── 001-urldecode.php │ ├── 001-urlencode.php │ └── 001-vsprintf.php ├── opcode │ ├── 001-assign_concat.php │ ├── 001-concat.php │ ├── 001-do_fcall.php │ ├── 001-do_fcall_by_name.php │ ├── 001-do_icall.php │ ├── 001-do_ucall.php │ ├── 001-echo.php │ ├── 001-exit.php │ ├── 001-fast_concat.php │ ├── 001-include_or_eval.php │ ├── 001-init_dynamic_call.php │ ├── 001-init_method_call.php │ ├── 001-init_user_call.php │ └── 001-rope_end.php └── sink │ ├── file │ ├── 001-copy.php │ ├── 001-dir.php │ ├── 001-file.php │ ├── 001-file_get_contents.php │ ├── 001-file_put_contents.php │ ├── 001-fopen.php │ ├── 001-glob.php │ ├── 001-highlight_file.php │ ├── 001-link.php │ ├── 001-move_uploaded_file.php │ ├── 001-opendir.php │ ├── 001-readfile.php │ ├── 001-rename.php │ ├── 001-rmdir.php │ ├── 001-scandir.php │ ├── 001-show_source.php │ └── 001-unlink.php │ ├── rce │ ├── 001-exec.php │ ├── 001-passthru.php │ ├── 001-popen.php │ ├── 001-proc_open.php │ ├── 001-shell_exec.php │ ├── 001-system.php │ └── 001-unserialize.php │ ├── sqli │ ├── 001-mysqli.php │ ├── 001-mysqli_init.php │ ├── 001-mysqli_multi_query.php │ ├── 001-mysqli_prepare.php │ ├── 001-mysqli_query.php │ ├── 001-mysqli_real_query.php │ ├── 001-pdo.php │ ├── 001-pg_prepare.php │ ├── 001-pg_query.php │ ├── 001-pg_query_params.php │ ├── 001-pg_send_prepare.php │ ├── 001-pg_send_query.php │ ├── 001-pg_send_query_params.php │ ├── 001-sqlite3.php │ └── config.php │ ├── ssrf │ ├── 001-curl_exec.php │ ├── 001-file_get_contents.php │ ├── 001-fsockopen.php │ └── 001-get_headers.php │ └── xss │ ├── 001-print_r.php │ ├── 001-printf.php │ └── 001-vprintf.php ├── tools ├── fuzzer.php └── fuzzer.py └── travis-php.ini /.gitignore: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/.gitignore -------------------------------------------------------------------------------- /.travis.yml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/.travis.yml -------------------------------------------------------------------------------- /Dockerfile: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/Dockerfile -------------------------------------------------------------------------------- /LICENSE: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/LICENSE -------------------------------------------------------------------------------- /README.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/README.md -------------------------------------------------------------------------------- /README.zh-CN.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/README.zh-CN.md -------------------------------------------------------------------------------- /artwork/dvwa_sentry_index.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/artwork/dvwa_sentry_index.png -------------------------------------------------------------------------------- /artwork/sentry_detail.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/artwork/sentry_detail.png -------------------------------------------------------------------------------- /composer.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/composer.json -------------------------------------------------------------------------------- /dvwa/Dockerfile: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/dvwa/Dockerfile -------------------------------------------------------------------------------- /dvwa/README.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/dvwa/README.md -------------------------------------------------------------------------------- /dvwa/README.zh-CN.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/dvwa/README.zh-CN.md -------------------------------------------------------------------------------- /dvwa/config.inc.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/dvwa/config.inc.php -------------------------------------------------------------------------------- /dvwa/entrypoint.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/dvwa/entrypoint.php -------------------------------------------------------------------------------- /dvwa/prvd.ini: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/dvwa/prvd.ini -------------------------------------------------------------------------------- /entrypoint.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/entrypoint.php -------------------------------------------------------------------------------- /phpunit.xml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/phpunit.xml -------------------------------------------------------------------------------- /prvd.ini: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/prvd.ini -------------------------------------------------------------------------------- /src/Client.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/Client.php -------------------------------------------------------------------------------- /src/Config.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/Config.php -------------------------------------------------------------------------------- /src/Entry.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/Entry.php -------------------------------------------------------------------------------- /src/Utils.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/Utils.php -------------------------------------------------------------------------------- /src/filter/001-base64_decode.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/filter/001-base64_decode.php -------------------------------------------------------------------------------- /src/filter/001-basename.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/filter/001-basename.php -------------------------------------------------------------------------------- /src/filter/001-dirname.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/filter/001-dirname.php -------------------------------------------------------------------------------- /src/filter/001-explode.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/filter/001-explode.php -------------------------------------------------------------------------------- /src/filter/001-gzuncompress.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/filter/001-gzuncompress.php -------------------------------------------------------------------------------- /src/filter/001-hex2bin.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/filter/001-hex2bin.php -------------------------------------------------------------------------------- /src/filter/001-html_entity_decode.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/filter/001-html_entity_decode.php -------------------------------------------------------------------------------- /src/filter/001-htmlspecialchars_decode.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/filter/001-htmlspecialchars_decode.php -------------------------------------------------------------------------------- /src/filter/001-implode.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/filter/001-implode.php -------------------------------------------------------------------------------- /src/filter/001-join.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/filter/001-join.php -------------------------------------------------------------------------------- /src/filter/001-json_decode.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/filter/001-json_decode.php -------------------------------------------------------------------------------- /src/filter/001-ltrim.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/filter/001-ltrim.php -------------------------------------------------------------------------------- /src/filter/001-pathinfo.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/filter/001-pathinfo.php -------------------------------------------------------------------------------- /src/filter/001-rawurldecode.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/filter/001-rawurldecode.php -------------------------------------------------------------------------------- /src/filter/001-rawurlencode.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/filter/001-rawurlencode.php -------------------------------------------------------------------------------- /src/filter/001-rtrim.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/filter/001-rtrim.php -------------------------------------------------------------------------------- /src/filter/001-sprintf.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/filter/001-sprintf.php -------------------------------------------------------------------------------- /src/filter/001-str_ireplace.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/filter/001-str_ireplace.php -------------------------------------------------------------------------------- /src/filter/001-str_pad.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/filter/001-str_pad.php -------------------------------------------------------------------------------- /src/filter/001-str_replace.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/filter/001-str_replace.php -------------------------------------------------------------------------------- /src/filter/001-strstr.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/filter/001-strstr.php -------------------------------------------------------------------------------- /src/filter/001-strtolower.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/filter/001-strtolower.php -------------------------------------------------------------------------------- /src/filter/001-strtoupper.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/filter/001-strtoupper.php -------------------------------------------------------------------------------- /src/filter/001-substr.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/filter/001-substr.php -------------------------------------------------------------------------------- /src/filter/001-trim.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/filter/001-trim.php -------------------------------------------------------------------------------- /src/filter/001-urldecode.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/filter/001-urldecode.php -------------------------------------------------------------------------------- /src/filter/001-urlencode.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/filter/001-urlencode.php -------------------------------------------------------------------------------- /src/filter/001-vsprintf.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/filter/001-vsprintf.php -------------------------------------------------------------------------------- /src/opcode/001-assign_concat.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/opcode/001-assign_concat.php -------------------------------------------------------------------------------- /src/opcode/001-concat.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/opcode/001-concat.php -------------------------------------------------------------------------------- /src/opcode/001-do_fcall.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/opcode/001-do_fcall.php -------------------------------------------------------------------------------- /src/opcode/001-do_fcall_by_name.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/opcode/001-do_fcall_by_name.php -------------------------------------------------------------------------------- /src/opcode/001-do_icall.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/opcode/001-do_icall.php -------------------------------------------------------------------------------- /src/opcode/001-do_ucall.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/opcode/001-do_ucall.php -------------------------------------------------------------------------------- /src/opcode/001-echo.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/opcode/001-echo.php -------------------------------------------------------------------------------- /src/opcode/001-exit.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/opcode/001-exit.php -------------------------------------------------------------------------------- /src/opcode/001-fast_concat.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/opcode/001-fast_concat.php -------------------------------------------------------------------------------- /src/opcode/001-include_or_eval.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/opcode/001-include_or_eval.php -------------------------------------------------------------------------------- /src/opcode/001-init_dynamic_call.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/opcode/001-init_dynamic_call.php -------------------------------------------------------------------------------- /src/opcode/001-init_method_call.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/opcode/001-init_method_call.php -------------------------------------------------------------------------------- /src/opcode/001-init_user_call.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/opcode/001-init_user_call.php -------------------------------------------------------------------------------- /src/opcode/001-rope_end.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/opcode/001-rope_end.php -------------------------------------------------------------------------------- /src/sink/file/001-copy.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/file/001-copy.php -------------------------------------------------------------------------------- /src/sink/file/001-dir.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/file/001-dir.php -------------------------------------------------------------------------------- /src/sink/file/001-file.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/file/001-file.php -------------------------------------------------------------------------------- /src/sink/file/001-file_get_contents.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/file/001-file_get_contents.php -------------------------------------------------------------------------------- /src/sink/file/001-file_put_contents.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/file/001-file_put_contents.php -------------------------------------------------------------------------------- /src/sink/file/001-fopen.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/file/001-fopen.php -------------------------------------------------------------------------------- /src/sink/file/001-glob.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/file/001-glob.php -------------------------------------------------------------------------------- /src/sink/file/001-highlight_file.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/file/001-highlight_file.php -------------------------------------------------------------------------------- /src/sink/file/001-link.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/file/001-link.php -------------------------------------------------------------------------------- /src/sink/file/001-move_uploaded_file.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/file/001-move_uploaded_file.php -------------------------------------------------------------------------------- /src/sink/file/001-opendir.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/file/001-opendir.php -------------------------------------------------------------------------------- /src/sink/file/001-readfile.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/file/001-readfile.php -------------------------------------------------------------------------------- /src/sink/file/001-rename.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/file/001-rename.php -------------------------------------------------------------------------------- /src/sink/file/001-rmdir.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/file/001-rmdir.php -------------------------------------------------------------------------------- /src/sink/file/001-scandir.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/file/001-scandir.php -------------------------------------------------------------------------------- /src/sink/file/001-show_source.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/file/001-show_source.php -------------------------------------------------------------------------------- /src/sink/file/001-unlink.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/file/001-unlink.php -------------------------------------------------------------------------------- /src/sink/rce/001-exec.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/rce/001-exec.php -------------------------------------------------------------------------------- /src/sink/rce/001-passthru.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/rce/001-passthru.php -------------------------------------------------------------------------------- /src/sink/rce/001-popen.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/rce/001-popen.php -------------------------------------------------------------------------------- /src/sink/rce/001-proc_open.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/rce/001-proc_open.php -------------------------------------------------------------------------------- /src/sink/rce/001-shell_exec.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/rce/001-shell_exec.php -------------------------------------------------------------------------------- /src/sink/rce/001-system.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/rce/001-system.php -------------------------------------------------------------------------------- /src/sink/rce/001-unserialize.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/rce/001-unserialize.php -------------------------------------------------------------------------------- /src/sink/sqli/001-mysqli.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/sqli/001-mysqli.php -------------------------------------------------------------------------------- /src/sink/sqli/001-mysqli_init.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/sqli/001-mysqli_init.php -------------------------------------------------------------------------------- /src/sink/sqli/001-mysqli_multi_query.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/sqli/001-mysqli_multi_query.php -------------------------------------------------------------------------------- /src/sink/sqli/001-mysqli_prepare.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/sqli/001-mysqli_prepare.php -------------------------------------------------------------------------------- /src/sink/sqli/001-mysqli_query.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/sqli/001-mysqli_query.php -------------------------------------------------------------------------------- /src/sink/sqli/001-mysqli_real_query.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/sqli/001-mysqli_real_query.php -------------------------------------------------------------------------------- /src/sink/sqli/001-pdo.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/sqli/001-pdo.php -------------------------------------------------------------------------------- /src/sink/sqli/001-pg_prepare.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/sqli/001-pg_prepare.php -------------------------------------------------------------------------------- /src/sink/sqli/001-pg_query.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/sqli/001-pg_query.php -------------------------------------------------------------------------------- /src/sink/sqli/001-pg_query_params.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/sqli/001-pg_query_params.php -------------------------------------------------------------------------------- /src/sink/sqli/001-pg_send_prepare.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/sqli/001-pg_send_prepare.php -------------------------------------------------------------------------------- /src/sink/sqli/001-pg_send_query.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/sqli/001-pg_send_query.php -------------------------------------------------------------------------------- /src/sink/sqli/001-pg_send_query_params.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/sqli/001-pg_send_query_params.php -------------------------------------------------------------------------------- /src/sink/sqli/001-sqlite3.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/sqli/001-sqlite3.php -------------------------------------------------------------------------------- /src/sink/ssrf/001-curl_exec.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/ssrf/001-curl_exec.php -------------------------------------------------------------------------------- /src/sink/ssrf/001-fsockopen.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/ssrf/001-fsockopen.php -------------------------------------------------------------------------------- /src/sink/ssrf/001-get_headers.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/ssrf/001-get_headers.php -------------------------------------------------------------------------------- /src/sink/xss/001-print_r.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/xss/001-print_r.php -------------------------------------------------------------------------------- /src/sink/xss/001-printf.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/xss/001-printf.php -------------------------------------------------------------------------------- /src/sink/xss/001-vprintf.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/src/sink/xss/001-vprintf.php -------------------------------------------------------------------------------- /test.sh: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/test.sh -------------------------------------------------------------------------------- /tests/bootstrap.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/tests/bootstrap.php -------------------------------------------------------------------------------- /tests/filter/001-base64_decode.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/tests/filter/001-base64_decode.php -------------------------------------------------------------------------------- /tests/filter/001-basename.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/tests/filter/001-basename.php -------------------------------------------------------------------------------- /tests/filter/001-dirname.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/tests/filter/001-dirname.php -------------------------------------------------------------------------------- /tests/filter/001-explode.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/tests/filter/001-explode.php -------------------------------------------------------------------------------- /tests/filter/001-gzuncompress.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/tests/filter/001-gzuncompress.php -------------------------------------------------------------------------------- /tests/filter/001-hex2bin.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/tests/filter/001-hex2bin.php -------------------------------------------------------------------------------- /tests/filter/001-html_entity_decode.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/tests/filter/001-html_entity_decode.php -------------------------------------------------------------------------------- /tests/filter/001-htmlspecialchars_decode.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/tests/filter/001-htmlspecialchars_decode.php -------------------------------------------------------------------------------- /tests/filter/001-implode.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/tests/filter/001-implode.php -------------------------------------------------------------------------------- /tests/filter/001-join.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/tests/filter/001-join.php -------------------------------------------------------------------------------- /tests/filter/001-json_decode.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/tests/filter/001-json_decode.php -------------------------------------------------------------------------------- /tests/filter/001-ltrim.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/tests/filter/001-ltrim.php -------------------------------------------------------------------------------- /tests/filter/001-pathinfo.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/tests/filter/001-pathinfo.php -------------------------------------------------------------------------------- /tests/filter/001-rawurldecode.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/tests/filter/001-rawurldecode.php -------------------------------------------------------------------------------- /tests/filter/001-rawurlencode.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/tests/filter/001-rawurlencode.php -------------------------------------------------------------------------------- /tests/filter/001-rtrim.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/tests/filter/001-rtrim.php -------------------------------------------------------------------------------- /tests/filter/001-sprintf.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/tests/filter/001-sprintf.php -------------------------------------------------------------------------------- /tests/filter/001-str_ireplace.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/tests/filter/001-str_ireplace.php -------------------------------------------------------------------------------- /tests/filter/001-str_pad.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/tests/filter/001-str_pad.php -------------------------------------------------------------------------------- /tests/filter/001-str_replace.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/tests/filter/001-str_replace.php -------------------------------------------------------------------------------- /tests/filter/001-strstr.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/tests/filter/001-strstr.php -------------------------------------------------------------------------------- /tests/filter/001-strtolower.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/tests/filter/001-strtolower.php -------------------------------------------------------------------------------- /tests/filter/001-strtoupper.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/tests/filter/001-strtoupper.php -------------------------------------------------------------------------------- /tests/filter/001-substr.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/tests/filter/001-substr.php -------------------------------------------------------------------------------- /tests/filter/001-trim.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/tests/filter/001-trim.php -------------------------------------------------------------------------------- /tests/filter/001-urldecode.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/tests/filter/001-urldecode.php -------------------------------------------------------------------------------- /tests/filter/001-urlencode.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/tests/filter/001-urlencode.php -------------------------------------------------------------------------------- /tests/filter/001-vsprintf.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/tests/filter/001-vsprintf.php -------------------------------------------------------------------------------- /tests/opcode/001-assign_concat.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/tests/opcode/001-assign_concat.php -------------------------------------------------------------------------------- /tests/opcode/001-concat.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/tests/opcode/001-concat.php -------------------------------------------------------------------------------- /tests/opcode/001-do_fcall.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/tests/opcode/001-do_fcall.php -------------------------------------------------------------------------------- /tests/opcode/001-do_fcall_by_name.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/tests/opcode/001-do_fcall_by_name.php -------------------------------------------------------------------------------- /tests/opcode/001-do_icall.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/tests/opcode/001-do_icall.php -------------------------------------------------------------------------------- /tests/opcode/001-do_ucall.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/tests/opcode/001-do_ucall.php -------------------------------------------------------------------------------- /tests/opcode/001-echo.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/fate0/prvd/HEAD/tests/opcode/001-echo.php -------------------------------------------------------------------------------- /tests/opcode/001-exit.php: -------------------------------------------------------------------------------- 1 |