Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
liffy — Local file inclusion exploitation tool | Kitploit
Tools/GitHubGitHub/mzfr/liffy
Vulnerability AnalysisWeb Application ExploitationWAF BypassPenetration TestingPayload Development
GitHubmzfr/liffy

liffy

Local file inclusion exploitation tool

View Repository
978114704 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

GitSpo Mentions License: GPL v3 Maintenance Rawsec's CyberSecurity Inventory

Packaging status


liffy

Advanced LFI Exploitation Tool

liffy in action

A powerful Python tool for Local File Inclusion (LFI) exploitation with advanced features including WAF bypass, encoding techniques, and comprehensive vulnerability detection.

Liffy v2.0 is the significantly enhanced version of liffy which was originally created by rotlogix/liffy. This version includes modern features like Rich terminal output, YAML configuration, enhanced threading, and multiple advanced exploitation techniques.

⚠️ Lot of new changes were vibe coded.

Table of Contents

  • Features
  • Installation
  • Usage
  • Configuration
  • Advanced Techniques
  • Examples
  • Contribution
  • Credits

Features

Core LFI Techniques

  • data:// - Code execution via data wrapper
  • expect:// - Code execution via expect wrapper
  • input:// - Code execution via input wrapper
  • filter:// - Arbitrary file reads via filter wrapper
  • /proc/self/environ - Code execution in CGI mode
  • Apache access.log poisoning - Log file exploitation
  • Linux auth.log SSH poisoning - SSH log exploitation
  • Null Byte Poisoning - Legacy PHP null byte attacks
  • ZIP wrapper exploitation - ZIP file inclusion attacks
  • Wrapper detection - Safe probes for common LFI stream wrappers
  • Out-of-band probes - Callback payloads for blind wrapper/SSRF-style behavior
  • Blind LFI checks - Response-difference probes when file contents are not reflected
  • Auto scan mode - Safe detection-first scan plan across traversal, wrappers, and blind checks

Advanced Features

  • WAF Evasion - Multiple bypass techniques for common WAFs
  • Advanced Encoding - Double URL encoding, Unicode, case variations
  • POST Request Support - Full POST method support with custom data
  • Custom Headers - Configurable HTTP headers
  • User-Agent Rotation - Randomized user agents to avoid detection
  • Rate Limiting - Configurable request throttling
  • Multi-threading - Enhanced thread pool management
  • Detection Mode - Vulnerability scanning without exploitation
  • Rich Terminal Output - Beautiful colored output with progress bars
  • YAML Configuration - Persistent settings management

Modern Enhancements

  • Enhanced Vulnerability Detection - Advanced response analysis with confidence scoring
  • Thread Pool Management - Optimized performance with adaptive threading
  • Configuration Management - YAML-based settings with CLI overrides
  • Comprehensive Logging - Detailed execution reports and progress tracking

Installation

Make sure you are using Python 3. Liffy doesn't support Python 2. The examples below use uv run python so commands run inside the project environment.

# Install uv if you haven't already
curl -LsSf https://astral.sh/uv/install.sh | sh

# Clone the repository
git clone https://github.com/mzfr/liffy
cd liffy

# Create virtual environment with uv
uv venv

# Install dependencies from pyproject.toml
uv sync

# Run liffy
uv run python liffy.py --help

Usage

Basic Syntax

uv run python liffy.py <URL> [OPTIONS]

Command Line Options

usage: liffy.py [-h] [-d] [-i] [-e] [-f] [-p] [-a] [-ns] [-r] [--ssh]
                [-l LOCATION] [--cookies COOKIES] [-dt] [-t THREADS]
                [--detection] [--null-byte] [--zip] [--encoding]
                [--waf-bypass] [--method {GET,POST}] [--post-data POST_DATA]
                [--headers HEADERS] [--lhost LHOST] [--lport LPORT]
                [--read-file READ_FILE] [-y] [--timeout TIMEOUT]
                [--proxy PROXY] [--verify-tls] [--user-agent USER_AGENT]
                [--oob] [--oob-url OOB_URL] [--blind] [--auto]
                [--delay DELAY] [--retries RETRIES] [--json] [--output OUTPUT]
                [--quiet] [--no-color] [--no-banner] [--config]
                [url]

positional arguments:
  url                   URL to test for LFI

Core Techniques:
  -d, --data            Use data:// technique
  -i, --input           Use input:// technique
  -e, --expect          Use expect:// technique
  -f, --filter          Use filter:// technique
  -p, --proc            Use /proc/self/environ technique
  -a, --access          Apache access logs technique
  --ssh                 SSH auth log poisoning
  -dt, --directorytraverse  Test for Directory Traversal
  --null-byte           Test for Null Byte Poisoning
  --zip                 Test for ZIP wrapper exploitation
  --wrappers, --wrapper Detect common LFI stream wrappers
  --wrapper-list WRAPPER_LIST
                        Path to custom wrapper probe payload list
  --oob                 Send out-of-band callback probes
  --oob-url OOB_URL     OOB callback base URL
  --blind               Run blind LFI response-difference checks
  --blind-list BLIND_LIST
                        Path to custom blind LFI probe list
  --auto                Run a safe automatic scan plan

Advanced Options:
  --encoding            Use advanced encoding/bypass techniques
  --waf-bypass          Use WAF evasion techniques
  --method {GET,POST}   HTTP method to use (default: GET)
  --post-data POST_DATA POST data (format: key=value&key2=value2)
  --headers HEADERS     Custom headers (format: Header1:Value1,Header2:Value2)
  --detection           Only perform LFI detection, no exploitation

Request Options:
  --timeout TIMEOUT     HTTP request timeout in seconds
  --proxy PROXY         HTTP(S) proxy URL, e.g. http://127.0.0.1:8080
  --verify-tls          Verify TLS certificates instead of using insecure requests
  --user-agent UA       Custom User-Agent header
  --delay DELAY         Delay between requests in seconds
  --retries RETRIES     HTTP retries per request

Automation Options:
  --lhost LHOST         Callback host for staged payloads
  --lport LPORT         Callback port for staged payloads
  --read-file PATH      File path to read with filter://
  -y, --yes             Use defaults for prompts and run non-interactively
  --json                Print a JSON run summary
  --output OUTPUT       Write JSON run summary to a file
  --quiet               Suppress normal terminal output

General Options:
  -ns, --nostager       Execute payload directly, do not use stager
  -r, --relative        Use path traversal sequences for attack
  -l, --location LOCATION  Path to target file (access log, auth log, etc.)
  --cookies COOKIES     Session cookies for authentication
  -t, --threads THREADS Number of threads to use (default: 5)
  --no-color            Disable colored output
  --no-banner           Disable banner display
  --config              Create default YAML configuration file

Configuration

YAML Configuration

Download Tool