RE: [TUT]RFI ( Remote File Inclusion ) 11-01-2011, 11:47 AM
#6
Before uploading a php make sure have this php.ini
the settings for RFI is this.
safe_mode = off ( a lot of shit cannot be done with this on )
disabled_functions = N/A ( no one,we want all )
register_globals = on ( we can set variables by request )
allow_url_include = on ( for lfi/rfi )
allow_url_fopen = on ( for lfi/rfi )
magic_quotes_gpc = off ( this will escape ‘ †and NUL’s with a backslash and we don’t want that )
short_tag_open = on ( some scripts are using short tags,better on )
file_uploads = on ( we want to upload )
display_errors = on ( we want to see the script errors,maybe some undeclared variables? )
The webhost not allow this
allow_url_fopen = on ( for lfi/rfi ) but its OFF
allow_url_include= on ( for lfi/rfi ) but its OFF
display_errors = on ( we want to see the script errors,maybe some undeclared variables? ) but its OFF
register_globals = on ( we can set variables by request ) but its OFF
magic_quotes_gpc = off ( this will escape ‘ †and NUL’s with a backslash and we don’t want that ) but its OFF.
I would say the webhosting will not check users accounts becouse of this settings.
the settings for RFI is this.
safe_mode = off ( a lot of shit cannot be done with this on )
disabled_functions = N/A ( no one,we want all )
register_globals = on ( we can set variables by request )
allow_url_include = on ( for lfi/rfi )
allow_url_fopen = on ( for lfi/rfi )
magic_quotes_gpc = off ( this will escape ‘ †and NUL’s with a backslash and we don’t want that )
short_tag_open = on ( some scripts are using short tags,better on )
file_uploads = on ( we want to upload )
display_errors = on ( we want to see the script errors,maybe some undeclared variables? )
The webhost not allow this
allow_url_fopen = on ( for lfi/rfi ) but its OFF
allow_url_include= on ( for lfi/rfi ) but its OFF
display_errors = on ( we want to see the script errors,maybe some undeclared variables? ) but its OFF
register_globals = on ( we can set variables by request ) but its OFF
magic_quotes_gpc = off ( this will escape ‘ †and NUL’s with a backslash and we don’t want that ) but its OFF.
I would say the webhosting will not check users accounts becouse of this settings.


![[Image: screenshot14be.jpg]](http://img841.imageshack.us/img841/4990/screenshot14be.jpg)
![[+]](https://sinister.li/images/modern/collapse_collapsed.png)