File Upload to RCE
Turn a file upload into code execution by defeating type/extension checks.
Tags: upload, rce, webshell, bypass
Level: intermediate
Method
Map the upload + retrieval
Find where the file lands and whether it's web-accessible. No exec path? Look for secondary sinks (image processing, archive extraction).
Tools: Burp Suite, ffuf
Bypass extension filters
Try double extensions (.php.jpg), alternate handlers (.phtml, .php5), case tricks, null bytes on legacy stacks, and .htaccess overrides.
Bypass content checks
Spoof Content-Type, prepend valid magic bytes (GIF89a;), or embed code in EXIF/polyglots to pass MIME/image validation.
exiftool -Comment='<?php system($_GET[c]); ?>' shell.jpgTools: exiftool
Chain the exotic
SVG → stored XSS/XXE, ZIP → path traversal (zip-slip), image libs → ImageMagick/Ghostscript RCE.
Field notes
- If uploads aren't executable, pivot: SVG/HTML for XSS, or overwrite files via traversal in the filename.
- Test what the CDN/origin does with unknown extensions - behavior often differs.