You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PHP file_get_contents路径遍历漏洞扩展利用技术咨询

Exploiting Path Traversal Beyond Config Files: Additional High-Impact Methods

Great question—you’ve already nailed the core path traversal flaw in the code (note: your original snippet is missing a concatenation dot, but the traversal logic still holds):

echo(file_get_contents("template/data/" . $_GET['id']));

Even with the template/data/ prefix and localhost-only database restriction, there are several ways to ramp up the vulnerability’s impact beyond just reading config files. Here are the most impactful avenues to explore:

  • Steal System-Level Authentication Credentials & Keys
    Look beyond MySQL credentials to target files that grant direct server access:

    • Linux: /etc/shadow (hashed user passwords, if readable), /home/<username>/.ssh/id_rsa (SSH private keys—exfiltrating this lets you SSH into the server as that user), /root/.ssh/id_rsa (root-level access if permissions allow).
    • Windows: C:\Users\<username>\.ssh\id_rsa, C:\Windows\System32\config\SAM (hashed local user passwords).
      These are far more critical than config files because they enable full server control, not just access to unused database credentials.
  • Exfiltrate Web Server & Application Logs
    Web logs often hold sensitive data that leads to account takeover:

    • Apache: /var/log/apache2/access.log, /var/log/apache2/error.log
    • Nginx: /var/log/nginx/access.log, /var/log/nginx/error.log
      Scan for unencrypted login requests (which may expose plaintext passwords), valid session IDs, or admin panel URLs. For example, a valid admin session cookie from logs lets you impersonate the admin directly in your browser—bypassing all login barriers.
  • Compromise User Sessions via PHP Session Files
    PHP stores session data in files by default (usually /var/lib/php/sessions/sess_<SESSION_ID> on Linux). If you can get a valid session ID (from logs, or by tricking a user into using your controlled ID), read the corresponding session file to extract:

    • Admin authentication flags (e.g., is_admin = 1)
    • User personal data (emails, payment info, private messages)
      This lets you take over user or admin accounts without cracking passwords.
  • Replicate the Entire Source Code Repository
    Many developers leave Git repo files on production servers. Use traversal to read .git directory contents:

    • Start with .git/HEAD to find the current branch
    • Extract objects from .git/objects/ to reconstruct the full codebase
      This can reveal unpatched vulnerabilities, hardcoded secrets in unreleased code, or API keys that weren’t present in live config files.
  • Map Internal Server Infrastructure
    Gain insight into the server’s setup to plan lateral movement:

    • Linux: /proc/net/tcp (lists open TCP ports and active connections), /proc/cpuinfo//proc/meminfo (hardware specs), /etc/services (service-to-port mappings)
    • Windows: C:\Windows\System32\drivers\etc\hosts (internal DNS entries), C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History (server user’s browser history)
      This helps you spot other internal vulnerable services, even if they’re not exposed to the internet.
  • Retrieve Backup & Temporary Files
    Developers often leave backups (e.g., index.php.bak, config.php.old) or temporary upload files (e.g., /tmp/phpXXXXXX on Linux) on servers. These may contain older, less secure code with more exposed secrets, or unprocessed user uploads that could be repurposed for future exploitation.

All these methods elevate the vulnerability’s impact from "reading configs" to full system compromise, account takeover, or large-scale data exfiltration—far more severe than just accessing unused database credentials.

内容的提问来源于stack exchange,提问作者GMX Rider

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 03:35:36