#!/usr/bin/env php / // laravel vuln // here how to encrypt and decrypt with API_Key https://github.com/laravel/framework/blob/6.x/src/Illuminate/Encryption/Encrypter.php // when enc or dec it's serialize and unserialize // so we can exploit php object injection to create file or get RCE // please check some Ref: // https://blog.truesec.com/2020/02/12/from-s3-bucket-to-laravel-unserialize-rce/ // https://github.com/kozmic/laravel-poc-CVE-2018-15133