![]() |
|
LFI & File extension bypass? - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Hacking (https://sinister.li/Forum-Hacking) +--- Forum: Website & Server Hacking (https://sinister.li/Forum-Website-Server-Hacking) +--- Thread: LFI & File extension bypass? (/Thread-LFI-File-extension-bypass) |
LFI & File extension bypass? - superMAUS - 05-10-2014 So just wondering say I come across something like this: file=/sdsd/sdsd/file Lets presume file is referring to file.html, is there anyway I can bypass the fact that the file will be handled as $_GET['file'] + ".html"? Say with # or something? Thanks, RE: LFI & File extension bypass? - tortilla - 05-10-2014 (05-10-2014, 02:27 PM)vegimite Wrote: So just wondering say I come across something like this: Try adding null at end. file=/sdsd/sdsd/file%00 RE: LFI & File extension bypass? - superMAUS - 05-10-2014 (05-10-2014, 02:36 PM)tortilla Wrote: Try adding null at end.Thanks very much tortilla, do you know if this the only method you can utilize? RE: LFI & File extension bypass? - rootaccess - 05-12-2014 maybe u find this link interesting http://diablohorn.wordpress.com/2010/01/16/interesting-local-file-inclusion-method/ RE: LFI & File extension bypass? - Cake - 05-12-2014 (05-12-2014, 06:45 PM)rootaccess Wrote: maybe u find this link interesting I found that link interesting. And now I know a couple more things I can do to secure my stuff. RE: LFI & File extension bypass? - rootaccess - 05-12-2014 (05-12-2014, 07:02 PM)Kodo Wrote: I found that link interesting. you are welcome man. i just searched google for local file inclusion bypasses
RE: LFI & File extension bypass? - superMAUS - 05-13-2014 Thanks @rootaccess, looks interesting. RE: LFI & File extension bypass? - rootaccess - 05-13-2014 You are welcome peeps Just trying to share to this Awesome community
|