fuzzdb/attack/lfi
2016-03-09 19:02:35 -05:00
..
common-ms-httpd-log-locations.fuzz.txt doc relocation and renaming update 2015-09-11 19:39:11 -04:00
common-unix-httpd-log-locations.fuzz.txt doc relocation and renaming update 2015-09-11 19:39:11 -04:00
JHADDIX_LFI.fuzz.txt Create JHADDIX_LFI.fuzz.txt 2016-03-09 19:02:35 -05:00
README.md Update README.md 2016-03-09 18:59:10 -05:00

LFI - Local File Include attacks

To exploit an LFI bug, you need to be able to write code to a local file and call it from the include. HTTPD log files are a location that is typically writable.

common-unix-httpd-log-locations.fuzz.txt

  • To exploit a lfi bug, you have to get code into a local file. This list contains a list of common unix logfile locations based on common packages formats.

common-windows-httpd-log-locations.fuzz.txt

  • To exploit a lfi bug, you have to get code into a local file. This list contains a list of common windows logfile locations based on common packages formats.

For more details:

other tools: