File upload to RCE

Where an HTTP file server accepts uploads and the upload directory is both web-served and allowed to execute scripts, uploading a web shell in the server's language yields code execution when the file is requested. The work is bypassing the upload filters (extension allowlists, content-type checks, magic-byte checks) and locating the uploaded file's URL.

bash
# Upload a shell, bypassing a naive extension filter
curl -F 'file=@shell.phar' http://<target>/upload       # alternate PHP extension
curl -F 'file=@shell.php;type=image/png' http://<target>/upload   # content-type spoof
curl 'http://<target>/uploads/shell.phar?cmd=id'         # trigger

Exploitation notes#

  • Match the payload to the server runtime: .php/.phar for PHP, .jsp/.jspx for Java, .aspx for IIS; the directory must be allowed to execute that type.
  • Common bypasses: alternate extensions, double extensions, content-type spoofing, trailing characters, and null or path tricks in the filename.
  • The exhaustive upload-bypass technique set lives in the Web area; this applies it to file-server upload.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more