<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; php-file-inclusion-vulnerability</title>
	<atom:link href="http://www.darknet.org.uk/tag/php-file-inclusion-vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>FIS [File Inclusion Scanner] v0.1 &#8211; PHP Vulnerability</title>
		<link>http://www.darknet.org.uk/2006/09/fis-file-inclusion-scanner-v01-php-vulnerability/</link>
		<comments>http://www.darknet.org.uk/2006/09/fis-file-inclusion-scanner-v01-php-vulnerability/#comments</comments>
		<pubDate>Mon, 25 Sep 2006 04:48:24 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Security Software]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[file-inclusion]]></category>
		<category><![CDATA[file-inclusion-scanner]]></category>
		<category><![CDATA[FIS]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[php-file-inclusion-vulnerability]]></category>
		<category><![CDATA[php-include]]></category>
		<category><![CDATA[php-includes]]></category>
		<category><![CDATA[php-vulnerability]]></category>
		<category><![CDATA[web-application-security]]></category>
		<category><![CDATA[website-auditing]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/09/fis-file-inclusion-scanner-v01-php-vulnerability/</guid>
		<description><![CDATA[A useful tool for anyone working with PHP applications. DESCRIPTION &#8212;&#8212;&#8212;&#8212; FIS (File Inclusion Scanner) is a vulnerability scanner for PHP applications. Is scans PHP files mapping PHP/HTTP variables and then performs a security audit,in order to find out which of them are exploitable. USAGE &#8212;&#8212; php fis.php [local file] [remote file] [remote FIS ID [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>A useful tool for anyone working with PHP applications.</p>
<p><strong>DESCRIPTION</strong><br />
&#8212;&#8212;&#8212;&#8212;<br />
FIS (File Inclusion Scanner) is a vulnerability scanner for PHP applications. Is scans PHP files mapping PHP/HTTP variables and then performs a security audit,in order to find out which of them are exploitable.</p>
<p><strong>USAGE</strong><br />
&#8212;&#8212;<br />
php fis.php [local file] [remote file] [remote FIS ID file]</p>
<p><strong>[local file]</strong><br />
&#8212;&#8212;&#8212;&#8212;&#8211;<br />
The local copy of the PHP source file used by FIS to map the variables for the audit.</p>
<p><strong>[remote file]</strong><br />
&#8212;&#8212;&#8212;&#8212;&#8211;<br />
The remote copy of the source executed by a remote webserver, the file we will audit.</p>
<p><strong>[remote FIS ID file]</strong><br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
The FIS ID file is used to check whether a variable is exploitable or not. It contains PHP code that simply echoes a unique MD5 hash used for identification.</p>
<p><strong>INTENDED AUDIENCE</strong><br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
FIS is intended to be used by penetration testers, not script kidies nor malicious users. It creates a lot of noise on the remote host and can be easily discovered with a simple glance at<br />
the webserver logs, which makes it useless as a cracking tool.</p>
<p><strong>FEATURES</strong><br />
&#8212;&#8212;&#8212;<br />
FIS, currently, supports audits using only GET requests. COOKIE &#038; POST support is not yet implemented.</p>
<p><strong>LOGGING</strong><br />
&#8212;&#8212;&#8212;<br />
FIS automatically logs extra audit information in &#8220;fis.log&#8221; in the working directory.</p>
<p><a href="http://segfault.gr/projects/?lang=en&#038;projects_id=11&#038;secid=28">FIS Website</a></p>
<p></p>
<p>You can <a href="http://segfault.gr/projects/releases/download.php?release_id=37">download FIS directly here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=FIS+%5BFile+Inclusion+Scanner%5D+v0.1+%E2%80%93+PHP+Vulnerability+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D350+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/09/fis-file-inclusion-scanner-v01-php-vulnerability/&amp;t=FIS+%5BFile+Inclusion+Scanner%5D+v0.1+%E2%80%93+PHP+Vulnerability" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/09/fis-file-inclusion-scanner-v01-php-vulnerability/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/09/fis-file-inclusion-scanner-v01-php-vulnerability/&amp;title=FIS+%5BFile+Inclusion+Scanner%5D+v0.1+%E2%80%93+PHP+Vulnerability" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/09/fis-file-inclusion-scanner-v01-php-vulnerability/&amp;title=FIS+%5BFile+Inclusion+Scanner%5D+v0.1+%E2%80%93+PHP+Vulnerability" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/09/fis-file-inclusion-scanner-v01-php-vulnerability/&amp;title=FIS+%5BFile+Inclusion+Scanner%5D+v0.1+%E2%80%93+PHP+Vulnerability" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/09/fis-file-inclusion-scanner-v01-php-vulnerability/&amp;title=FIS+%5BFile+Inclusion+Scanner%5D+v0.1+%E2%80%93+PHP+Vulnerability" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F09%2Ffis-file-inclusion-scanner-v01-php-vulnerability%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/09/fis-file-inclusion-scanner-v01-php-vulnerability/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
	</channel>
</rss>

