Where an HTTP file server accepts uploads and the upload directory is both web-served and allowed to execute scripts, uploading a web shell in the server's language yields code execution when the file is requested. The work is bypassing the upload filters (extension allowlists, content-type checks, magic-byte checks) and locating the uploaded file's URL.
# Upload a shell, bypassing a naive extension filter
curl -F 'file=@shell.phar' http://<target>/upload # alternate PHP extension
curl -F 'file=@shell.php;type=image/png' http://<target>/upload # content-type spoof
curl 'http://<target>/uploads/shell.phar?cmd=id' # trigger
Exploitation notes#
- Match the payload to the server runtime:
.php/.pharfor PHP,.jsp/.jspxfor Java,.aspxfor IIS; the directory must be allowed to execute that type. - Common bypasses: alternate extensions, double extensions, content-type spoofing, trailing characters, and null or path tricks in the filename.
- The exhaustive upload-bypass technique set lives in the Web area; this applies it to file-server upload.