<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; rfi</title>
	<atom:link href="http://www.darknet.org.uk/tag/rfi/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>fimap &#8211; Remote &amp; Local File Inclusion (RFI/LFI) Scanner</title>
		<link>http://www.darknet.org.uk/2010/01/fimap-remote-local-file-inclusion-rfilfi-scanner/</link>
		<comments>http://www.darknet.org.uk/2010/01/fimap-remote-local-file-inclusion-rfilfi-scanner/#comments</comments>
		<pubDate>Tue, 05 Jan 2010 09:39:12 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[audit tool]]></category>
		<category><![CDATA[fimap]]></category>
		<category><![CDATA[hacking tool]]></category>
		<category><![CDATA[hacking-web-applications]]></category>
		<category><![CDATA[lfi]]></category>
		<category><![CDATA[lfi scanner]]></category>
		<category><![CDATA[local file inclusion]]></category>
		<category><![CDATA[remote file inclusion]]></category>
		<category><![CDATA[rfi]]></category>
		<category><![CDATA[rfi scanner]]></category>
		<category><![CDATA[web-application-security]]></category>
		<category><![CDATA[web-security]]></category>
		<category><![CDATA[webapp security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2390</guid>
		<description><![CDATA[fimap is a little python tool which can find, prepare, audit, exploit and even google automatically for local and remote file inclusion bugs in webapps. fimap is similar to sqlmap just for LFI/RFI bugs instead of sql injection. It is currently under heavy development but it’s usable. Features Check a Single URL, List of URLs, [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>fimap is a little python tool which can find, prepare, audit, exploit and even google automatically for local and remote file inclusion bugs in webapps. fimap is similar to <a href="http://www.darknet.org.uk/2009/07/sqlmap-0-7-released-automatic-sql-injection-tool/">sqlmap</a> just for LFI/RFI bugs instead of sql injection. It is currently under heavy development but it’s usable.</p>
<p><strong>Features</strong></p>
<ul>
<li>Check a Single URL, List of URLs, or Google results fully automatically.</li>
<li>Can identify and exploit file inclusion bugs.</li>
<li>Test and exploit multiple bugs</li>
<li>Has an interactive exploit mode</li>
<li>Add your own payloads and patches to the config.py file.</li>
<li>Has a Harvest mode which can collect URLs from a given domain for later pentesting.</li>
<li>Can use proxies (experimental).</li>
</ul>
<p><strong>Changes</strong></p>
<ul>
<li>All commands will now be send base64 encoded. So you can use quotes as much as you want.</li>
<li>php://input detection is now 100% reliable.</li>
<li>You can now define a POST string for relative and absolute files in the config.py.</li>
<li>TTL implemented. You can define it with &#8220;—ttl &#8220;. Default is 30 seconds.</li>
<li>Experimental HTTP Proxy support. You can define a HTTP(s) proxy with &#8220;—http-proxy localhost:8080&#8243;.</li>
<li>Googlescanner can now skip the first X pages. Use &#8220;—skip-pages X&#8221;.</li>
<li>Lots of bugfixes and additional regular expressions.</li>
</ul>
<p><strong>Requirements</strong></p>
<ul>
<li>Needs: Python >= 2.4</li>
</ul>
<p>You can download fimap here:</p>
<p><a href="http://fimap.googlecode.com/files/fimap_alpha_v07.tar.gz">fimap_alpha_v07.tar.gz</a></p>
<p></p>
<p>Or read more <a href="http://code.google.com/p/fimap/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=fimap+%E2%80%93+Remote+%26+Local+File+Inclusion+%28RFI%2FLFI%29+Scanner+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2390+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/01/fimap-remote-local-file-inclusion-rfilfi-scanner/&amp;t=fimap+%E2%80%93+Remote+%26+Local+File+Inclusion+%28RFI%2FLFI%29+Scanner" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/01/fimap-remote-local-file-inclusion-rfilfi-scanner/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/01/fimap-remote-local-file-inclusion-rfilfi-scanner/&amp;title=fimap+%E2%80%93+Remote+%26+Local+File+Inclusion+%28RFI%2FLFI%29+Scanner" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/01/fimap-remote-local-file-inclusion-rfilfi-scanner/&amp;title=fimap+%E2%80%93+Remote+%26+Local+File+Inclusion+%28RFI%2FLFI%29+Scanner" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/01/fimap-remote-local-file-inclusion-rfilfi-scanner/&amp;title=fimap+%E2%80%93+Remote+%26+Local+File+Inclusion+%28RFI%2FLFI%29+Scanner" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/01/fimap-remote-local-file-inclusion-rfilfi-scanner/&amp;title=fimap+%E2%80%93+Remote+%26+Local+File+Inclusion+%28RFI%2FLFI%29+Scanner" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F01%2Ffimap-remote-local-file-inclusion-rfilfi-scanner%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/01/fimap-remote-local-file-inclusion-rfilfi-scanner/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Damn Vulnerable Web App &#8211; Learn &amp; Practise Web Hacking</title>
		<link>http://www.darknet.org.uk/2009/07/damn-vulnerable-web-app-learn-practise-web-hacking/</link>
		<comments>http://www.darknet.org.uk/2009/07/damn-vulnerable-web-app-learn-practise-web-hacking/#comments</comments>
		<pubDate>Wed, 15 Jul 2009 08:39:59 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[damn vulnerable web app]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[hacking-websites]]></category>
		<category><![CDATA[lfi]]></category>
		<category><![CDATA[mysql]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[php mysql]]></category>
		<category><![CDATA[practise web hacking]]></category>
		<category><![CDATA[rfi]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[vulnerable web app]]></category>
		<category><![CDATA[vulnerable web application]]></category>
		<category><![CDATA[web-application-security]]></category>
		<category><![CDATA[web-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1913</guid>
		<description><![CDATA[Damn Vulnerable Web App (DVWA) is a PHP/MySQL web application that is damn vulnerable. Its main goals are to be light weight, easy to use and full of vulnerabilities to exploit. Used to learn or teach the art of web application security. Vulnerabilities SQL Injection XSS (Cross Site Scripting) LFI (Local File Inclusion) RFI (Remote [...]]]></description>
			<content:encoded><![CDATA[<p>Damn Vulnerable Web App (DVWA) is a PHP/MySQL web application that is damn vulnerable. Its main goals are to be light weight, easy to use and full of vulnerabilities to exploit. Used to learn or teach the art of web application security.</p>
<p><strong>Vulnerabilities</strong></p>
<ul>
<li>SQL Injection</li>
<li>XSS (Cross Site Scripting)</li>
<li>LFI (Local File Inclusion)</li>
<li>RFI (Remote File Inclusion)</li>
<li>Command Execution</li>
<li>Upload Script</li>
<li>Login Brute Force</li>
</ul>
<p><strong>Changes</strong></p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<ul>
<li>Added Acunetix scan report.</li>
<li>All links use http://hiderefer.com to hide referrer header.</li>
<li>Updated/added ‘more info’ links.</li>
<li>Moved change log info to CHANGELOG.txt.</li>
<li>Fixed the exec.php UTF-8 output.</li>
<li>Moved Help/View source buttons to footer.</li>
<li>Fixed phpInfo bug. </li>
<li>Made DVWA IE friendly.</li>
<li>Fixed html bugs.</li>
<li>Improved README.txt and fixed typos.</li>
<li>Made SQL injection possible in sqli_med.php.</li>
</ul>
<p><strong>WARNING</strong></p>
<p>It should come as no shock..but this application is damn vulnerable! Do not upload it to your hosting provider’s public html folder or any working web server as it will be hacked. It&#8217;s recommend that you download and install XAMP onto a local machine inside your LAN which is used solely for testing.</p>
<p>You can download DVWA 1.0.4 here:</p>
<p><a href="http://sourceforge.net/projects/dvwa/files/dvwa/dvwa_v1.0.4.zip/download">dvwa_v1.0.4.zip</a></p>
<p>Or read more <a href="http://sourceforge.net/projects/dvwa/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Damn+Vulnerable+Web+App+%E2%80%93+Learn+%26+Practise+Web+Hacking+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1913+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/07/damn-vulnerable-web-app-learn-practise-web-hacking/&amp;t=Damn+Vulnerable+Web+App+%E2%80%93+Learn+%26+Practise+Web+Hacking" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/07/damn-vulnerable-web-app-learn-practise-web-hacking/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/07/damn-vulnerable-web-app-learn-practise-web-hacking/&amp;title=Damn+Vulnerable+Web+App+%E2%80%93+Learn+%26+Practise+Web+Hacking" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/07/damn-vulnerable-web-app-learn-practise-web-hacking/&amp;title=Damn+Vulnerable+Web+App+%E2%80%93+Learn+%26+Practise+Web+Hacking" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/07/damn-vulnerable-web-app-learn-practise-web-hacking/&amp;title=Damn+Vulnerable+Web+App+%E2%80%93+Learn+%26+Practise+Web+Hacking" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/07/damn-vulnerable-web-app-learn-practise-web-hacking/&amp;title=Damn+Vulnerable+Web+App+%E2%80%93+Learn+%26+Practise+Web+Hacking" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F07%2Fdamn-vulnerable-web-app-learn-practise-web-hacking%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/07/damn-vulnerable-web-app-learn-practise-web-hacking/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
	</channel>
</rss>

