LFI Tutorial - Getting mysql db password

Loading...

Sign in or sign up now!
Alert icon
Upgrade to the latest Flash Player for improved playback performance. Upgrade now or more info.
3,392
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on Jan 18, 2009

Hackingtut0rials is back!

This tutorial concludes a method in LFI which gets you the mysql db password.

Category:

Science & Technology

Tags:

License:

Standard YouTube License

Link to this comment:

Share to:

Uploader Comments (HackingTut0rials)

  • And the img.php?img=../img.php is technically meaning to bypass that file. And you find it via google dorks. DUR.

  • LFI is common. You guys need to learn your own extensions. The site this was done on gave us +++++ security, because the owner of the site had a host stashed in it once we got in the mysql.

    Learn your security because LFI is sometimes used for shells, and RFI is familiar and you can use RFI to upload a shell.

    lrn2hax. kkthxbai.

see all

All Comments (3)

Sign In or Sign Up now to post a comment!
  • what is song?

  • sorry dude but I don't think a page with file_get_contents which lets you access the root directory or one dir up, or doesn't even check the file-to-read's extension is protected very well

    im not saying your method is impossible, just that you have to be very "lucky" to find such files

  • good luck finding such files with zero security

    maybe you could make a tutorial about how you can find upload services that dont have a file extension check so you can upload php scripts so you can remove their directories

    that will show them offering free upload space for free

Loading...

Alert icon
0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more