Thursday 29 September 2011

Scan For Files Vulnerable To LFI - LFIMAP


My last post was on Local File Inclusion(LFI) . LFI is a common website vulnerability and it is used for website hacking. There are some existing tools that deal with LFI vulnerabilities such as lfimap the Remote & Local File Inclusion (RFI/LFI) Scanner .


This new simple tool was released recently which focuses purely on LFI attacks. Test your website with this tool for LFI.


Functions:


  1. Automatically find the root of the file system
  2. Detect default files outside of the web folder
  3. Attempts to detect passwords inside the files
  4. Supports basic authentication
  5. Can use null byte to bypass some controls
  6. Writes a report of the scan to a file



Download here:
http://lfimap.googlecode.com/files/lfimap-1.4.3.tar.gz 

0 comments:

Post a Comment

 
Related Posts Plugin for WordPress, Blogger...