### High-Value Files and Directories to Check During Linux LFI: #### 1. **SSH Keys and Known Hosts** - **File(s)**: - `/home//.ssh/id_rsa` - Private RSA key. - `/home//.ssh/id_ecdsa` - Private ECDSA key. - `/home//.ssh/id_dsa` - Private DSA key. - `/home//.ssh/authorized_keys` - Authorized SSH keys for remote access. - `/home//.ssh/known_hosts` - Hosts previously accessed, possibly helping with network mapping. - `/etc/ssh/ssh_config` - Global SSH client configuration. - `/etc/ssh/sshd_config` - SSH daemon configuration, may contain port information and other details useful for lateral movement. #### 2. **User and System Credentials** - **File(s)**: - `/etc/passwd` - Contains system user accounts; combined with `/etc/shadow`, it can reveal password hashes. - `/etc/shadow` - Stores hashed passwords; access may depend on privilege level. - `/etc/group` - Lists group memberships, which may reveal sudo users. - `/var/spool/mail/` - Often contains user email files that may contain passwords or other sensitive information. - `/etc/sudoers` - Can reveal sudo privileges and any user-specific rules. #### 3. **Database Configurations and Passwords** - **File(s)**: - `/var/www/html/wp-config.php` - Common WordPress configuration file containing database credentials. - `/var/www/html/.env` - Environment configuration files used by various applications; may contain database credentials and other secrets. - `/root/.my.cnf` - MySQL configuration file containing root credentials. - `/etc/mysql/my.cnf` - Default MySQL configuration; can reveal useful info for database connections. - `/opt//.env` - Application-specific configuration files for services like Laravel, Django, Node.js, which can store sensitive information. #### 4. **Web Application Configuration Files** - **File(s)**: - `/var/www/html/config.php` - Often used by PHP-based web applications. - `/var/www/html/.htaccess` - Access control configuration for Apache; can reveal access restrictions and environment details. - `/var/www/html/.htpasswd` - Stores username and password pairs for basic authentication. - `/usr/local/etc/nginx/nginx.conf` - Nginx web server configuration, may reveal proxy settings or other backend info. - `/etc/httpd/conf/httpd.conf` - Apache configuration file, useful for understanding directory permissions and access controls. #### 5. **Network and Application Logs** - **File(s)**: - `/var/log/auth.log` or `/var/log/secure` - Authentication logs, can show login attempts, successful or failed, potentially revealing usernames. - `/var/log/apache2/access.log` - Apache access logs, helpful for identifying traffic patterns or hidden endpoints. - `/var/log/nginx/access.log` - Nginx access logs, similar use to Apache logs. - `/var/log/mysql/error.log` - MySQL error logs, which may contain sensitive error messages. - `/var/log/messages` - General system logs that might contain application error information and sensitive data. #### 6. **System and Network Configuration** - **File(s)**: - `/etc/network/interfaces` - Network interface configurations for Debian-based systems. - `/etc/resolv.conf` - DNS resolver configuration. - `/etc/hosts` - Local hostname-to-IP mappings. - `/proc/net/tcp` - Active TCP connections and ports; useful for identifying open services and potential pivoting targets. - `/etc/hostname` - System hostname, which could help map network assets. #### 7. **Cron Jobs and Scheduled Tasks** - **File(s)**: - `/etc/crontab` - System-wide cron jobs. - `/var/spool/cron/crontabs/` - User-specific cron jobs, which might reveal periodic tasks that could be exploitable. - `/etc/cron.d/` - Another location for cron jobs, particularly for application-specific scheduling. - `/etc/at.allow` and `/etc/at.deny` - Lists for controlling access to the `at` scheduler, revealing scheduled tasks and potential privilege escalation opportunities. #### 8. **Application and Service-Specific Files** - **File(s)**: - `/etc/postgresql/*/main/pg_hba.conf` - PostgreSQL authentication configuration. - `/etc/redis/redis.conf` - Redis configuration, possibly containing credentials or IP restrictions. - `/opt/tomcat/conf/tomcat-users.xml` - Tomcat user configuration; can contain admin-level credentials for the Tomcat server. - `/etc/ldap/ldap.conf` - LDAP configuration; may help with Active Directory queries. - `/etc/docker/daemon.json` - Docker configuration, useful if docker is used within the environment.