I am in the module File Inclusion in the section of PHP Filters. I am stucked regarding “Fuzz the web application for other php scripts, and then read one of the configuration files and submit the database password as the answer”. I tried on idex.php, on languages=en/es with the “php://filter/read=convert.base64-encode/resource=config” but nothing. I did ffuf on the machine but found only index.php and configure but nothing also. Anyone can help me ?
its just in Front of you.
You found the php files index.php and configure.php but are trying to get the config.php file. You see the mistake?