Thirteen Years of Service
Posts: 144
Threads: 51
RE: FI (Remote File Inclusion) 04-08-2012, 04:12 PM
#12
if i will prov it then ,.,.,.,.,.,.,.,.,.,
i think ur fool trying 2 prov owner of site
(This post was last modified: 04-08-2012, 04:13 PM by ZerQl.)
•
Thirteen Years of Service
Posts: 3,169
Threads: 99
RE: FI (Remote File Inclusion) 01-24-2013, 11:40 AM
#14
Just as a note on the original article, regardless of who wrote it... but i thought id point out that RFI does not necessarily lead to complete control of a server. Best case scenario yes. Average scenario is that you get access to the account that the website account is running under. It would be stupid to have a website running under root. You also only get access to the PHP code that is specifically allowed, so you probably cant run *any* command you want on a relatively secure server.
With RFI and C99 you will get access to the account and website, but not necessarily the server. There is a difference.
Okay i swear this was just on the todays threads page, but it says the last response was like 7 months ago. sorry for the necropost.
•