--- name: hunt-upload description: File upload attack hunting - extension/content-type/magic-byte bypass to web-shell RCE, path traversal in filename, SVG/XML XSS, zip slip, and pixel-flood DoS. Wiki-first, FIND schema output. --- # Hunt: File Upload **Assumes `hunt-core`** for the scope gate, two-account rule, confirmation gate, enumeration limits, stop conditions, wiki protocol, FIND output, and Deadends. Do not re-derive any of that here. ## Wiki ``` qmd_query "file upload webshell extension content-type magic-byte bypass SVG XXE zip slip path traversal" via wiki-search MCP ``` Hub: [[web-moc]] (live index). Primary page: [[file-upload]]. Payload arsenal: `wiki/payloads/file-upload.md`. Anchors: [[path-traversal-lfi]]. ## Attack surface Rank the sinks first - not every upload reaches code: - **Avatar / profile / logo / signature fields** - most common; frequently re-encoded, so check whether the original bytes are served back. - **Document / CSV / XML import** - parser sinks (XXE, formula injection, zip). - **Ticket / message attachments** - often served under the original name and type from a reachable path. - **Image-processing** (thumbnails -> ImageMagick/Ghostscript), SVG/PDF render, EXIF parsers - the processor is the bug, not the store. - **Firmware / plugin / theme upload** - direct code load; highest value when present. Then attack in layers, cheapest first: **extension -> content-type -> magic-byte -> parser/render.** ## Methodology 1. **Baseline:** upload a valid file; note stored path, returned URL, filename transformation, and whether it is reachable + executed by the server. 2. **Extension bypass:** ``` shell.php shell.phtml shell.php5 shell.phar shell.pHp shell.php.jpg shell.jpg.php shell.php%00.jpg shell.php;.jpg shell.php/ shell.php.... (trailing dot/space on Windows) .htaccess -> AddType application/x-httpd-php .jpg (then upload .jpg shell) web.config (IIS) .jsp/.jspx/.war (Java) .asp/.aspx (IIS) ``` 3. **Content-Type / magic-byte bypass:** set `Content-Type: image/png`; prepend real magic bytes (`GIF89a;`, `\xFF\xD8\xFF` JPEG, `%PDF-`) before the payload; polyglot (valid image + PHP). 4. **Path traversal in filename:** `filename="../../../../var/www/html/shell.php"` to escape the upload dir / overwrite files. 5. **SVG / XML:** SVG with `