xsspresso
xsspresso
Tags/ LFI

LFI

12 writeups tagged with LFI

WebMediumLinux

HTB — Facts

Cacti LFI via CVE-2024-46987 reads configuration files and credentials. Sudo abuse on a custom binary escalates to root.

#Cacti#LFI#CVE-2024-46987
Mar 8, 2026HackTheBox
WebEasyLinux

VHL — Trails

Hiking Trails web application on Ubuntu. Directory traversal and file inclusion vulnerabilities lead to credentials and shell.

#LFI#Directory Traversal#Apache
Feb 12, 2025Virtual Hacking Labs
ADMediumWindows

HTB — StreamIO

SQLi on login page, LFI reveals PHP source. MSSQL xp_cmdshell for shell. Firefox DPAPI credential decryption leads to Domain Admin via ADCS.

#AD#SQLi#LFI
Jan 31, 2025HackTheBox
ADHardWindows

HTB — Flight

LFI via lang parameter captures NTLM hash with Responder. Password spray, IIS WebDAV shell upload, RunasCs for lateral movement to Domain Admin.

#AD#LFI#NTLM
Jan 21, 2025HackTheBox
WebEasyLinux

HTB — Tabby

LFI on Tomcat manager exposes credentials. WAR file deployed for RCE. ZIP password cracking, LXD container privilege escalation for root.

#LFI#Tomcat#WAR
Nov 26, 2024HackTheBox
WebMediumWindows

HTB — Sniper

PHP RFI via language parameter loads SMB share for RCE. Lateral movement via credential in web config. CHM file drops reverse shell as Administrator.

#RFI#SMB#CHM
Nov 21, 2024HackTheBox
MiscEasyWindows

HTB — ServMon

Anonymous FTP reveals NVMS-1000 path traversal note. LFI reads credentials file, SSH pivoting to access NSClient++ for SYSTEM.

#FTP#LFI#NVMS-1000
Nov 20, 2024HackTheBox
WebMediumLinux

HTB — UpDown

Site availability checker with .htaccess allowlist bypass. PHP phar deserialization for code execution, proc_open for shell, developer sudo suid binary.

#PHAR Deserialization#LFI#Bypass
Nov 19, 2024HackTheBox
WebEasyLinux

HTB — Friendzone

DNS zone transfer reveals subdomains. SMB anonymous share leaks creds. LFI + PHP injection for RCE, Python lib hijack for root.

#SMB#LFI#DNS
Apr 23, 2022HackTheBox
WebMediumLinux

HTB — Poison

PHP LFI escalated to RCE via Apache log poisoning. SSH tunneling exposes an internal VNC session running as root.

#LFI#Log Poisoning#VNC
Apr 10, 2022HackTheBox
WebMediumLinux

HTB — Nineveh

Brute-force phpLiteAdmin + LFI via chained PHP injection. Port knocking unlocks SSH, chkrootkit path hijack for root.

#Brute Force#LFI#Port Knocking
Mar 28, 2022HackTheBox
MiscEasyLinux

HTB — Beep

Multiple valid paths: Elastix LFI to leak credentials, Webmin RCE, or Asterisk extension abuse. Great enumeration practice.

#Elastix#LFI#Webmin
Mar 26, 2022HackTheBox