🧨My LFI Methodology
TIP: file:///etc/passwd : Not authorized
file://\/\/etc/passwd : Work
---------------------------------------------------------------
TIP: file:///etc/passwd blacklisted?
Use "view-source:file:///etc/passwd" "view-source" is often forgotten by developers in blacklists.
---------------------------------------------------------------
File Download to Check LFI
File Download Path Send to Burp intruder
---------------------------------------------------------------
Check LFI Methods
File Download Path Send to Burp Repeater
-------------------------------------------------------------
Top 25 parameters



---------------------------------------------------------------
Local file inclusion at filemanager.php Endpoint
Parameter: path=
Payload: //....//....//....//....//....//....//....//....//....//etc/passwd
----------------------------------------------------------------
LFI Automate this with a one-liner
----------------------------------------------------------------
(1) One-Liner LFI Finding
----------------------------------------------------------------
(2) One-Liner LFI Finding
----------------------------------------------------------------
(3) One-Liner LFI Finding
----------------------------------------------------------------
(4) One-Liner LFI Finding
----------------------------------------------------------------
(5) One-Liner LFI Finding
----------------------------------------------------------------
(6) One-Liner NGINX LFI Finding
----------------------------------------------------------------
(7) One-Liner LFI Finding
----------------------------------------------------------------
(8) One-Liner LFI Finding
----------------------------------------------------------------
(8) One-Liner LFI Finding
----------------------------------------------------------------
(9) One-Liner LFI Finding
----------------------------------------------------------------
(10) One-Liner LFI Finding
----------------------------------------------------------------
(11) One-Liner LFI Finding
----------------------------------------------------------------
(12) One-Liner LFI Finding
----------------------------------------------------------------
Endpoint of attack parameter
----------------------------------------------------------------
How to Find LFI Manual Using Burp Hackbar
----------------------------------------------------------------
How to Find LFI Using Burp Intruder | LFI Payload.txt
----------------------------------------------------------------
How to Find LFI Using wayback | gf | Burp Hackbar
----------------------------------------------------------------
How to Find LFI Using wayback | gf | Burp Intruder | LFI Payload.txt
----------------------------------------------------------------
Last updated