Laravel APP_KEY leakage analysis #1091
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
🤖 Automated Content Update
This PR was automatically generated by the HackTricks News Bot based on a technical blog post.
📝 Source Information
🎯 Content Summary
Technical Summary of Laravel Encryption and Exploitation
Encryption Implementation
Laravel’s encryption is implemented in the
Illuminate\Encryption\Encrypter
class using AES-256-CBC with a randomly generated IV, HMAC integrity, and optional serialization.Encrypted output is a base64-encoded JSON object with fields
iv
,value
,mac
, andtag
.Example Encryption
...🔧 Technical Details
Laravel’s default
decrypt($payload)
method unserializes its output ($unserialize = true
), allowing an attacker with knowledge of theAPP_KEY
to craft encrypted serialized PHP objects wrapped in the Encrypter’s JSON format (iv
/value
/mac
/tag
) and base64-encode them to achieve RCE via magic methods.Using PHPGGC, attackers can generate Laravel gadget chains (e.g., RCE13, RCE9, RCE15) that trigger 🤖 Agent Actions
Added advanced Laravel APP_KEY exploitation content:
decrypt()
unserialize vector.All changes appended to existing
pentesting-web/laravel.md
while preserving original material.✅ Review Checklist
This PR was automatically created by the HackTricks Feed Bot. Please review the changes carefully before merging.
📚 Repository Maintenance
All .md files have been checked for proper formatting (headers, includes, etc.).