https://github.com/francescodisalesgithub/pwrap
command line utility for testing php local file inclusion
https://github.com/francescodisalesgithub/pwrap
builder cookie file-inclusion hacking hacking-tool hackingcode php php5 php7 requests requests-mo requests-python snippets tool wrapper yaml
Last synced: 2 months ago
JSON representation
command line utility for testing php local file inclusion
- Host: GitHub
- URL: https://github.com/francescodisalesgithub/pwrap
- Owner: FrancescoDiSalesGithub
- License: gpl-3.0
- Created: 2021-08-18T11:14:22.000Z (almost 4 years ago)
- Default Branch: main
- Last Pushed: 2022-06-02T17:58:14.000Z (almost 3 years ago)
- Last Synced: 2025-01-19T17:56:14.720Z (4 months ago)
- Topics: builder, cookie, file-inclusion, hacking, hacking-tool, hackingcode, php, php5, php7, requests, requests-mo, requests-python, snippets, tool, wrapper, yaml
- Language: Python
- Homepage:
- Size: 40 KB
- Stars: 2
- Watchers: 1
- Forks: 0
- Open Issues: 0
-
Metadata Files:
- Readme: README.md
- License: LICENSE
Awesome Lists containing this project
README
# pwrap
command line utility for testing php local file inclusion## How to use
run:
`pip3 install -r requirements.txt`launch pwrap by following these rules:
` python3 pwrap.py [URL] [File inclusion entry point] [wrapper] [yaml filename]`
where:
* URL = the url location you want to test your LFI
* File Inclusion entry point = the parameter that is vulnerable to LFI
* wrapper = the possible wrapper that pwrap uses
* yaml filename = yaml file where there are cookies informationThe possible wrappers that pwrap uses are:
* file
* filter
* data
* zip
* expect
* input### Example usage
create a file with yaml extension and put the cookie informations:
```
---
"PHPSESSID": "abcderete43w",
"info1": "asdfasdad"
"info2": "sddskhfds"```
then run the program:
`python3 pwrap.py http://somesite.com/ page file example-file.yaml`If everything goes well, pwrap will open a browser window with the outcome of the local file inclusion
# Donation
If you want to support me donate monero coins at:
`4B9WQivaHfd3miDfPKEfCianocGpBx9d8FXycz2vmNW3aBDVKHgkBd9Gmapt4RBVEpTwnehujsiUBBehUiLvnEHs7VFstCC`
or here (0.0043 XMR):
