The script reach the end in the search of sourceforge.net for PHP scripts recently. But don’t worry, arfis will continue with download and checking scripts from hotscripts.com. Yeah, more RFI’s will come :).
Nutshell
What you see here is the output of the "arfis project", a simple perl script. It automatically downloads and extract PHP projects from sourceforge.net and checks for Remote File Inclusion vulnerabilities. It then post's the potential (now it's -potential-, cause the script is in an early stadium) vuln to this blog.
Contact: arfis@gmx.de
Contact: arfis@gmx.de
arfis status
Version: 0.3
Running: No
Running: No
todo
- get scripts from hotscripts.com
- check for .htaccess files wich could prevent RFI's
- check if the "variable" is DOCUMENT_ROOT or such
- other improvements
- check for .htaccess files wich could prevent RFI's
- check if the "variable" is DOCUMENT_ROOT or such
- other improvements
note
The found RFI's are not re-checked, nor if they work, nor if they were already found. Arfis is not a 100% valuable source, so don't blame it if you get a non working or existing RFI. Thanks.
a
Recent RFI’s
- Trustworthy
- Sourceforge.net sucked off
- RFI (0.3): php(Reactor)
- RFI (0.3): PHPortal
- RFI (0.3): YaPiG – Yet Another PHP Image Gallery
- RFI (0.3): myphpPagetool
- RFI (0.3): Webmedia Explorer
- RFI (0.3): Streamline PHP Media Server
- RFI (0.3): pSlash
- Version 0.3
- RFI (0.3): openEngine
- RFI (0.2): guanxiCRM Business Solution
- RFI (0.2): Online Fantasy Football League
- RFI (0.2): EZ-Ticket
- RFI (0.2): phpmyProfiler
disclaimer
This project is done for informational purpose only. The author is not responsible for damage of websites running exposed PHP scripts. Anyway, you are allowed to recheck the vulnerabilities posted on this site, inform the author(s) of the PHP project, and release it on sites like milw0rm. But please, give some credits to "arfis" if you do so.