Hacker News new | ask | show | jobs
by girvo 4355 days ago
I'm assuming the down votes are because you missed the point of your parent. The example uses a PHP script for uploading the payload, but that can be swapped out for nearly any language on a server. They all require an exploit to get the dropper on there anyway, so that's a barrier. PHP isn't the point here though, it's the interesting damage the exploit that gets pulled down by the dropper can achieve, without needing to use privilege escalation.