
Proof-of-concept LFI Scanner: Automated detection of /etc/passwd exposures via directory traversal and regex matching.
# LFI Scanner
A lightweight Python proof-of-concept to scan target hosts for Local File Inclusion (LFI) vulnerabilities by attempting to retrieve `/etc/passwd` and detecting its presence with a regex check. :contentReference[oaicite:0]{index=0}
## Features
- **Batch scanning** of hostnames or host:port targets from an input file
- **Directory traversal payload** to reach `/etc/passwd`
- **Regex detection** of the `root` entry to confirm LFI
- **Progress bar** powered by `tqdm` for real-time feedback
- **Structured reporting**: outputs findings and previews to a results file
## Prerequisites
- Python 3.6 or newer
- [`tqdm`](https://pypi.org/project/tqdm/) (`pip install tqdm`)
- `curl` CLI available in your PATH
## Installation
```bash
git clone https://github.com/yourusername/lfi-scanner.git
cd lfi-scanner
pip install tqdm
python poc.py <input_file> [-o OUTPUT_FILE]
<input_file>: Path to a file containing one target per line (hostname or hostname:port).-o, --output: (Optional) Path to write results (default: results.txt).Given targets.txt:
example.com
192.168.0.1:8443
Run the scanner:
python poc.py targets.txt -o scan_results.txt
You’ll see output like:
[+] https://example.com:443/... → /etc/passwd FOUND
[-] https://192.168.0.1:8443/... → Response received, no match
And scan_results.txt will contain a summary and previews.
poc.py:
argparse to parse --input and --output.curl --insecure -s for each target.root:.*?:0:0: to confirm /etc/passwd exposure.Use this tool responsibly and only on assets you own or have explicit permission to test. Unauthorized scanning may violate laws and terms of service.
Released under the MIT License.