LFI_Fuzzploit is a simple tool to help in the fuzzing
for, finding,and exploiting local file inclusions in Linux
based PHP applications. Using special encoding and fuzzing
techniques lfi_fuzzploit will scan for some known and some
not so known LFI filter bypasses and exploits using some
advanced encoding/bypass methods to try to bypass security
and achieve its goal which is ultimately, exploiting a
Local file inclusion.
In addition to LFI_fuzzploit's fuzzing and encoding techniques,
it also has built in methods for LFI exploitation including
/proc/self/environ shell exploit, File descriptor shell and
LFI shell via log injection. LFI_fuzzploit injects code using
different command injection functions in the event that certain
functions are disabled. Coded by nullbyt3.