lfi2rce-via-temp-file-uploads.md (2952B)
1 --- 2 title: "LFI to RCE via Temporary File Uploads" 3 section: "Web Pentesting" 4 sectionSlug: "pentesting-web" 5 sourcePath: "src/pentesting-web/file-inclusion/lfi2rce-via-temp-file-uploads.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/file-inclusion/lfi2rce-via-temp-file-uploads.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # LFI to RCE via Temporary File Uploads 14 15 **Check the full details of this technique in [https://gynvael.coldwind.pl/download.php?f=PHP_LFI_rfc1867_temporary_files.pdf](https://gynvael.coldwind.pl/download.php?f=PHP_LFI_rfc1867_temporary_files.pdf)**<sup>[[1]](#references)</sup> 16 17 ## **PHP File uploads** 18 19 When PHP receives a `multipart/form-data` POST containing a file upload, it stores the body in a temporary file. Application code can persist it with `move_uploaded_file()`; otherwise PHP removes it at the end of the request. The exploit races an LFI against that cleanup.<sup>[[1]](#references)[[2]](#references)</sup> 20 21 > [!TIP] 22 > **Security Alert: Attackers, aware of the temporary files' location, might exploit a Local File Inclusion vulnerability to execute code by accessing the file during upload.** 23 24 The challenge for unauthorized access lies in predicting the temporary file's name, which is intentionally randomized. 25 26 ### Exploitation on Windows Systems 27 28 In the historical Windows implementation described by the research, PHP used `GetTempFileName`, producing a name shaped like `<path>\<pre><uuuu>.TMP`. Notably: 29 30 - The default path is typically `C:\Windows\Temp`. 31 - The prefix is usually "php". 32 - The `<uuuu>` represents a unique hexadecimal value. Crucially, due to the function's limitation, only the lower 16 bits are used, allowing for a maximum of 65,535 unique names with constant path and prefix, making brute force feasible. 33 34 Moreover, the exploitation process is simplified on Windows systems. A peculiarity in the `FindFirstFile` function permits the use of wildcards in Local File Inclusion (LFI) paths. This enables crafting an include path like the following to locate the temporary file: 35 36 ```text 37 http://site/vuln.php?inc=c:\windows\temp\php<< 38 ``` 39 40 In certain situations, a more specific mask (like `php1<<` or `phpA<<`) might be required. One can systematically try these masks to discover the uploaded temporary file. 41 42 ### Exploitation on GNU/Linux Systems 43 44 On GNU/Linux, temporary names have substantially more entropy, so direct name brute force is generally impractical; other disclosure or race primitives may still expose the pathname.<sup>[[1]](#references)</sup> 45 46 ## References 47 48 - [1] [PHP LFI rfc1867 file upload temporary files (gynvael.coldwind.pl)](https://gynvael.coldwind.pl/download.php?f=PHP_LFI_rfc1867_temporary_files.pdf) 49 - [2] [PHP manual — POST method uploads](https://www.php.net/manual/en/features.file-upload.post-method.php)