{"repo":"flozz/p0wny-shell","free":true,"listed":false,"github":"https://github.com/flozz/p0wny-shell","clone":"git clone https://github.com/flozz/p0wny-shell.git","description":"Single-file PHP shell","language":"PHP","stars":2857,"topics":["php-shell","pentesting"],"license":"WTFPL","category":"security-tools","readme_excerpt":"p0wny@shell: # -- Single-file PHP Shell p0wny@shell: # is a very basic, single-file, PHP shell. It can be used to quickly execute commands on a server when pentesting a PHP application. Use it with caution: this script represents a security risk for the server. Features: Command history (using arrow keys ↑ ↓ ) Auto-completion of command and file names (using Tab key) Navigate on the remote file-system (using cd command) Upload a file to the server (using upload command) Download a file from the server (using download command) WARNING: THIS SCRIPT IS A SECURITY HOLE. DO NOT UPLOAD IT ON A SERVER UNLESS YOU KNOW WHAT YOU ARE DOING! Demo with Docker: docker build -t p0wny . docker run -it -p 8080:8080 -d p0wny # open with your browser http://127.0.0.1:8080/shell.php Contributing Questions If you have any question, you can: Open an issue on GitHub Ask on Discord (I am not always available to chat, but I try to answer to everyone) Bugs Please open an issue on GitHub with as much information as possible if you found a bug: Your operating system / Linux distribution (and its version) The PHP version you are using (example: PHP-FPM 8.1 , Apache mod php 7.4 ,...) The Web server you are using and its version (example: Nginx 1.23 , Apache 2.4.55 ,...) All the logs and message outputted by the software etc. Pull requests Please consider filing a bug before starting to work on a new feature; it will allow us to discuss the best way to do it. It is obviously unnecessary if you just want to","default_branch":null,"files":null,"tree":[],"storefront":"/r/flozz","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/flozz/p0wny-shell/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}