How can I inject code into PHP via vulnerable endpoint?

Viewed 280

I am trying myself on an 'easy' pentest box of HackTheBox. During my investigation I found an endpoint with a vulnerable variable example.php?file= that gets not sanitised.

Through path traversal I was able to retrieve /etc/passwd as well as the source code of example.php (payload file=./../../../../../../var/www/html/example.php) which is the following:

<?php
$file = $_GET['file'];
$fh = fopen("files/$file","r");
while ($line = fgets($fh)) {
  echo($line);
}
fclose($fh);
?>

Now I tried myself at injecting some addition PHP code into the example.php file but to no preveil. Given that what ever 'file' evaluates to gets put into fopen I tested the following payloads while trying to break out of the existing code:

  1. ","r");exec("whoami", $output);print_r($output);// get whoami returned in the response body, didn't work,, but gave a 200 response

  2. ","r");exec("nc -l -p 8080 -e /bin/bash");// setup netcat backdoor to send commands directly to a shell - didn't work

Can someone help me figure this one out? How can I successfuly perform some form of remote code injection here on this clearly vulnerable piece of code? Thank's in advance

0 Answers
Related