Jun 29, 2023, 01:24 AM
Hello
,
Today I would like to make you aware of the LFI. We see a lot of SQLI but LFI are just as dangerous.
For a demonstration we will take a random site :
https://www.vanillaforest.tw/
Anyway we look quickly and we find :
We could stop there, and simply try to break the hashes & connect in SSH... But, I am not x0rz whitehat for report to sys-admin.
So as a good son of a bitch. We're going to fuck this site
,Today I would like to make you aware of the LFI. We see a lot of SQLI but LFI are just as dangerous.
For a demonstration we will take a random site :
https://www.vanillaforest.tw/
Anyway we look quickly and we find :
index.php?page=about.phpWe could stop there, and simply try to break the hashes & connect in SSH... But, I am not x0rz whitehat for report to sys-admin.
So as a good son of a bitch. We're going to fuck this site
Since we can use filters (php://filter=...). We can try to make a chain to have an RCE.
takemyss@breached: ~/$ python3 php_filter_chain_generator.py --chain '<?php phpinfo(); ?>'
