Gadget Chain PoC
This module provides a testing tool for Gadget Chains in Drupal, allowing developers to send payloads to PHP's `unserialize()` function. It is intended for security testing only and should not be used on production sites.
This is a Security testing module intended to help test fixes for Gadget Chains (aka POP Chains) in Drupal applications.
[blink tag] This should never be installed on production. [/blink tag]
Features
The module simply provides a route which will pass a payload to PHP's unserialize().
The payload can be passed as a GET or a POST parameter, with the name payload.
By default, access to the route requires authentication as a user with the "administer site configuration" permission, so it would typically be necessary to include a valid session cookie with the request.
It's possible to bypass this restriction with the following in settings.php:
$settings['gadget_chain_poc_free_access'] = TRUE;
Use this override at your own risk, and with extreme caution.
Additional options
The following optional parameters can be passed along with the payload (the value is ignored).
base64- the payload will go through `base64_decode()` before being passed tounserialize().tostring- the unserialized object will be cast to a string, invoking the relevant__toString()magic method.output- display the result of the call tounserialize(); it will be pretty-printed as HTML by default, but can also be output as json if the GET param_format=jsonis sent in the request.
Depends on
Dependencies of the latest stable release
No dependencies recorded for this project.
Required by
Tracked projects that depend on this one
No tracked projects depend on this one yet.
Activity
Releases
| Version | Type | Core | Notes | Release date | |
|---|---|---|---|---|---|
| 1.0.x-dev | Dev | 8–11 | dev release (rolling) | Jan 23, 2025 |