Altoro Mutual – Get SHELL!

Altoro Mutual ~$ Known as “Hack me” site made by IBM. This site got all possible vulnerabilities as: “XXS, SQL Injection, RFI/LFI” and more. I’m going to skip “XSS” and “SQL” Injection in this Walkthrough, and proceed to “RFI/LFI” to get Shell.   ~$ Web Shell If we scan Altoro Mutual website with Burp Spider, we will detect that there …

