RFI question

No explicit questions like "how do I hack xxx.com" please!
Post Reply
User avatar
Kirk
suck-o enforcer
suck-o enforcer
Posts: 547
Joined: 25 Apr 2009, 16:00
14
Contact:

RFI question

Post by Kirk »

I'm just starting to learn about Remote File Inclussion so bear with me please. Would it be possible to have the target site run a program like Cain or something similar using RFI? I understand how to insert a file to exploit and exploit but can you have the site run an entire program?

User avatar
leetnigga
Fame ! Where are the chicks?!
Fame ! Where are the chicks?!
Posts: 447
Joined: 28 Jul 2009, 16:00
14

Post by leetnigga »

A Remote File Inclusion lets you run a remote PHP file. In this PHP file you can do anything you can normally do in PHP (within the limits of their configuration).

PHP has quite a few Program execution Functions that you can use to run programs on the server. If there is a Cain and Abel executable on the server, and you have permission to execute it, then it shouldn't be a problem.

Since Cain and Abel is graphical program, don't expect to be able to do much more than to open it.

Post Reply