Stars: 296
Forks: 81
Pull Requests: 6
Issues: 8
Watchers: 14
Last Updated: 2020-10-01 06:53:11
small set of PHP scripts to practice exploiting LFI, RFI and CMD injection vulns
License: MIT License
Languages: PHP, Makefile, Shell
small set of PHP scripts to practice exploiting LFI, RFI and CMD injection vulns
for training and testing purposes. you can test detection products (e.g. vulnerability scanners), exploit tools, etc.
these are NOT intended for evaluating appsec testing tools.
the idea is that you'd add these to an Apache VirtualHost directive for testing purposes. if you need to do some quick and dirty testing, fire up php -S 0.0.0.0:8080
or something and go to town.
three big options.
docker-compose up
vagrant up
jose nazario @jnazario
https://github.com/AUDI-1/sqli-labs