Web Server Exploitation with LFI and File Upload
In this article you will learn how to bypass file uploading vulnerability in high security through FILE INCLUSION vulnerability. As well as how to bypass local file inclusion to get reverse connection of victim’s Pc.
Attacker: kali Linux
Target: DVWA
First you need to download Exif Piot tool from here. This is a GUI tool for windows users which allow adding exif data and Meta data inside a JPEG, PNG and GIF images.
Now open exif pilot and insert any image to hide malicious comment inside it; from screenshot you can see I have choose shell.png image and then click on EDIT EXIF/IPTC.
Full Article Read Here
Security Expert, OSEP| OSCP| OSWP| CRTP| CRT, CPSA| CARTP| EWAPTX | ISO27001SLI | ISO27032 LM
8 年nice write up, well done