RFI

For beginners, flames not allowed...(just by the staff :P)
Post Reply
User avatar
zeus_zf
forum buddy
forum buddy
Posts: 21
Joined: 10 May 2006, 16:00
17
Contact:

RFI

Post by zeus_zf »

I have a RFI question. And I have hit a strange dead end.

I guess the question is not so much just how it is done, but I would like to have my "I" using a shell prompt of some sort.

I wonder first of all, to share with me the proper steps of a righteous RFI attack, and the second please, to share with me a nice shell.


====
So far, I have read and absorbed much material on this topic.

I have tried it, you know to test if they are vuln, you throw in a site like google, and if it is on the page somewhere, than you have a real victim.

Anyhow, I think I have the concept and idea, but there is a few things that just are not registering at all!

User avatar
ayu
Staff
Staff
Posts: 8109
Joined: 27 Aug 2005, 16:00
18
Contact:

Post by ayu »

So...what are these "things" then? ^^
"The best place to hide a tree, is in a forest"

User avatar
Lyecdevf
cyber Idi Amin
cyber Idi Amin
Posts: 1222
Joined: 16 Mar 2006, 17:00
18
Location: In between life and death.
Contact:

Re: RFI

Post by Lyecdevf »

zeus_zf wrote: you throw in a site like google, and if it is on the page somewhere, than you have a real victim.
Are you talking about a RFI scanner? If so mind sharing it with us because I would like to get my hands on one.
zeus_zf wrote:Anyhow, I think I have the concept and idea, but there is a few things that just are not registering at all!
RFI means Remote File Injection. This vulnerability on a PHP website allows you to force a website to load instead of it's own file a remote file that you have specified. So first of all you need that site and file that you are going to specify the website to load and is going to give you admin right on the victims website. If you see what I mean.
We will either find a way, or make one.
- Hannibal

User avatar
Deth
forum buddy
forum buddy
Posts: 24
Joined: 12 Jul 2006, 16:00
17

Post by Deth »

This may appear obvious, but I poked about, these things are perl scripts, and can be found on a couple of forums in google's cache, apparently give a lot of false positives, but may be effective, might be worth a look.

Post Reply