Abusing LFI-RFI for Fun,Profit and Shells

“This talk is about exploiting the much less discussed Local File Inclusion and Remote File Inclusion these days due to its extinction.The talk moves one step further and focuses on various new methods and strategies which are explained and demonstrated. The talk looks upon various real world scenarios and introduces new attack vectors and also dives deep into various methods and its demos. The talk also touches on various PHP streams which could be used to bypass the traditional streams. It also further looks upon suhosin patch, its bypass and other evasion techniques. The paper will also talk on the I2RCE.py tool which automates the inclusion process to remote session.”

Presented by