{"id":20847285,"url":"https://github.com/jsmoreira02/lfi-hunter","last_synced_at":"2025-03-12T11:43:18.947Z","repository":{"id":228035681,"uuid":"772992149","full_name":"Jsmoreira02/LFI-Hunter","owner":"Jsmoreira02","description":"Automated tool to bypass filtering systems and exploit Local File Inclusion, created for Bug Bounty tests and better optimization during the hack (and with special attention to CTFs)","archived":false,"fork":false,"pushed_at":"2024-09-22T08:54:26.000Z","size":20,"stargazers_count":0,"open_issues_count":0,"forks_count":1,"subscribers_count":2,"default_branch":"main","last_synced_at":"2025-01-19T05:38:08.040Z","etag":null,"topics":["bugbounty","ctf-tools","cybersecurity","hacking-tool","lfi-exploitation"],"latest_commit_sha":null,"homepage":"","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"gpl-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/Jsmoreira02.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null}},"created_at":"2024-03-16T12:51:38.000Z","updated_at":"2024-09-22T08:54:29.000Z","dependencies_parsed_at":"2024-03-16T15:25:47.443Z","dependency_job_id":"e24db422-5be4-4f8c-99cb-ada47171b2a7","html_url":"https://github.com/Jsmoreira02/LFI-Hunter","commit_stats":null,"previous_names":["jsmoreira02/lfi-hunter"],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Jsmoreira02%2FLFI-Hunter","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Jsmoreira02%2FLFI-Hunter/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Jsmoreira02%2FLFI-Hunter/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Jsmoreira02%2FLFI-Hunter/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/Jsmoreira02","download_url":"https://codeload.github.com/Jsmoreira02/LFI-Hunter/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":243213867,"owners_count":20254879,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["bugbounty","ctf-tools","cybersecurity","hacking-tool","lfi-exploitation"],"created_at":"2024-11-18T02:19:33.829Z","updated_at":"2025-03-12T11:43:18.926Z","avatar_url":"https://github.com/Jsmoreira02.png","language":"Python","funding_links":[],"categories":[],"sub_categories":[],"readme":"\u003cdiv\u003e\u003ccenter\u003e\n\n  \u003cimg src=\"https://github.com/Jsmoreira02/LFI-Hunter/assets/103542430/3b9e846a-f2dd-44a9-8329-0bcf7eabacfd\"\u003e\u003c/br\u003e\n  \n\u003c/center\u003e\u003c/div\u003e\n\n\u003cdiv align=\"center\"\u003e\n  \u003cimg src=\"https://img.shields.io/badge/Language%20-Python3-green.svg\"\u003e\n  \u003cimg src=\"https://img.shields.io/badge/License%20-GPL 2.0-blue.svg\"\u003e\n  \u003cimg src=\"https://img.shields.io/badge/Type%20-Hacking tool | CTF tool-darkblue.svg\"\"\u003e\n  \u003cimg src=\"https://img.shields.io/badge/OS%20-Windows, Linux-red.svg\"\"\u003e\n  \u003cimg src=\"https://img.shields.io/badge/Local File Inclusion%20-teste?style=flat-square\"\u003e\n\u003c/div\u003e\n\n\n# Hunt for LFI (Local File Inclusion)\nSimple Automated brute force attack tool for exploiting local file inclusion, using GET requests (with special attention to CTFs and bug bounty). Designed to optimize time spent searching for injections that bypass site security and filtering.\n\n-------\n# Local File Inclusion: \n``The File Inclusion vulnerability allows an attacker to include a file, usually exploiting a “dynamic file inclusion” mechanisms implemented in the target application. The vulnerability occurs due to the use of user-supplied input without proper validation. This can lead to something as outputting the contents of the file``\n\n- The script will use all the most commonly used techniques to bypass a filtering system or protections on the potentially vulnerable target and will show all successful payloads. If you know of an additional more effective technique, feel free to modify the code or add other payloads.\n\n![video](https://github.com/Jsmoreira02/LFI-Hunter/assets/103542430/4df2df13-d3a9-4421-a755-36f40370d21a)\n\n## Optionals:\n\n`-o/--output` --\u003e Prints the results of the exploit \n\n`-s/--saveToFile` --\u003e Save the results to a file\n\n# Warning:    \n\u003e I am not responsible for any illegal use or damage caused by this tool. It was written for fun, not evil and is intended to raise awareness about cybersecurity\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjsmoreira02%2Flfi-hunter","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fjsmoreira02%2Flfi-hunter","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjsmoreira02%2Flfi-hunter/lists"}