daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

lfi2rce-via-temp-file-uploads.md (2952B)


      1 ---
      2 title: "LFI to RCE via Temporary File Uploads"
      3 section: "Web Pentesting"
      4 sectionSlug: "pentesting-web"
      5 sourcePath: "src/pentesting-web/file-inclusion/lfi2rce-via-temp-file-uploads.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/file-inclusion/lfi2rce-via-temp-file-uploads.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # LFI to RCE via Temporary File Uploads
     14 
     15 **Check the full details of this technique in [https://gynvael.coldwind.pl/download.php?f=PHP_LFI_rfc1867_temporary_files.pdf](https://gynvael.coldwind.pl/download.php?f=PHP_LFI_rfc1867_temporary_files.pdf)**<sup>[[1]](#references)</sup>
     16 
     17 ## **PHP File uploads**
     18 
     19 When PHP receives a `multipart/form-data` POST containing a file upload, it stores the body in a temporary file. Application code can persist it with `move_uploaded_file()`; otherwise PHP removes it at the end of the request. The exploit races an LFI against that cleanup.<sup>[[1]](#references)[[2]](#references)</sup>
     20 
     21 > [!TIP]
     22 > **Security Alert: Attackers, aware of the temporary files' location, might exploit a Local File Inclusion vulnerability to execute code by accessing the file during upload.**
     23 
     24 The challenge for unauthorized access lies in predicting the temporary file's name, which is intentionally randomized.
     25 
     26 ### Exploitation on Windows Systems
     27 
     28 In the historical Windows implementation described by the research, PHP used `GetTempFileName`, producing a name shaped like `<path>\<pre><uuuu>.TMP`. Notably:
     29 
     30 - The default path is typically `C:\Windows\Temp`.
     31 - The prefix is usually "php".
     32 - The `<uuuu>` represents a unique hexadecimal value. Crucially, due to the function's limitation, only the lower 16 bits are used, allowing for a maximum of 65,535 unique names with constant path and prefix, making brute force feasible.
     33 
     34 Moreover, the exploitation process is simplified on Windows systems. A peculiarity in the `FindFirstFile` function permits the use of wildcards in Local File Inclusion (LFI) paths. This enables crafting an include path like the following to locate the temporary file:
     35 
     36 ```text
     37 http://site/vuln.php?inc=c:\windows\temp\php<<
     38 ```
     39 
     40 In certain situations, a more specific mask (like `php1<<` or `phpA<<`) might be required. One can systematically try these masks to discover the uploaded temporary file.
     41 
     42 ### Exploitation on GNU/Linux Systems
     43 
     44 On GNU/Linux, temporary names have substantially more entropy, so direct name brute force is generally impractical; other disclosure or race primitives may still expose the pathname.<sup>[[1]](#references)</sup>
     45 
     46 ## References
     47 
     48 - [1] [PHP LFI rfc1867 file upload temporary files (gynvael.coldwind.pl)](https://gynvael.coldwind.pl/download.php?f=PHP_LFI_rfc1867_temporary_files.pdf)
     49 - [2] [PHP manual — POST method uploads](https://www.php.net/manual/en/features.file-upload.post-method.php)