Files
oscp/Software/php/LFI.md
T
2025-11-21 17:17:42 +01:00

4.3 KiB
Raw Blame History

Working with Temporary Directories in RCE Exploits:

1. Alternate Temporary Directories:

  • Typical Situation: When executing code remotely on a Linux server, payloads often need to be stored in a temporary directory such as /tmp. However, some systems may restrict access to /tmp or clear it periodically, which could interrupt or prevent payload execution.
  • Solution: Use /dev/shm/ instead.
    • /dev/shm/ is an in-memory filesystem (tmpfs) on Linux, commonly used for temporary file storage with higher I/O performance since it resides in memory rather than on disk.
    • Advantages:
      • Less likely to be cleared automatically, especially if /tmp is periodically purged by the system.
      • Provides faster access speeds for payload execution.
      • Accessible to non-root users by default on many systems, making it ideal for user-level code execution.
      • /dev/shm/ is generally world-writable, meaning any user can write files here.

2. Using Other World-Writable Directories:

  • If both /tmp and /dev/shm/ are unavailable, consider other locations:
    • /var/tmp/: Another temporary directory, though typically less frequently cleared than /tmp.
    • User home directories: If the user running the web application service has a home directory, you may find writable directories here. However, these can vary in permissions.
    • Application-specific directories: Some web applications may have writable directories for uploads, cache, or session storage. Checking for world-writable application directories (e.g., /var/www/html/uploads/ for web applications) can yield alternative options for payload storage.

Understanding PrivateTmp=true in Apache and Other Services:

  • PrivateTmp Setting:

    • If a service like apache.service has PrivateTmp=true in its systemd configuration (/etc/systemd/system/apache.service or /lib/systemd/system/apache.service), the service is configured with an isolated, private temporary directory, separate from the systems global /tmp and /var/tmp/.
    • Implication: The services /tmp and /var/tmp are effectively "sandboxed," meaning that any files written to /tmp by Apache (or another service with this setting) wont be accessible from the global /tmp path, which could affect payload storage or retrieval.
    • Path Differences: For example, the actual temporary directories may appear under:
      • /tmp/systemd-private-<unique-id>-apache.service-<random>/tmp/
      • This directory is created by systemd for services with PrivateTmp=true, effectively isolating the service's /tmp space from other processes.
  • Bypassing PrivateTmp:

    • Use /dev/shm/ or other directories unaffected by PrivateTmp to store files that need to be accessible system-wide.
    • Modify systemd configuration (if possible with higher privileges): Setting PrivateTmp=false within the apache.service file and restarting the service may disable the isolated temporary storage, reverting the application to the global /tmp directory. However, this change requires root or appropriate sudo privileges.
    • Other File Paths: Even with PrivateTmp=true, paths like /dev/shm/ and /var/tmp/ remain globally accessible, so they can still be used as viable alternatives.

Additional Tips for RCE Payload Handling:

  • Environment Variables: Some RCE exploits allow manipulation of environment variables. If possible, set variables such as TMPDIR=/dev/shm/ within the application, which may direct temporary files to your chosen directory.
  • Upload Shells or Payloads: If the application allows for file uploads (e.g., image or document uploads), try uploading a payload to an accessible directory rather than relying on /tmp or /dev/shm/.
  • Custom Service Configurations: Sometimes, application-specific configuration files (e.g., PHP open_basedir restrictions) or Apache directives like php_admin_value might restrict file access. Check for these restrictions in web server configuration files such as httpd.conf or .htaccess files if you can access them.
  • Webshells and Command Execution: If possible, establish a web shell that allows direct command execution and file navigation, giving more flexibility in handling these directory restrictions.