Utility

Lfi Generator

A new tool extracted from the codebase.

Last reviewed by the Radiatus Cloud team

LFI Payload Generator

Generate Local File Inclusion (LFI) and Directory Traversal payloads to test file access controls.

Need this done properly for your business?

Radiatus delivers secure cloud, DevOps & compliance engineering.

Book a free consult

Test your own application for local file inclusion and path traversal

Testing whether your own application is vulnerable to local file inclusion and path traversal is part of securing it, and doing so requires understanding the vulnerability class. This tool helps you generate test cases for local file inclusion and path traversal so you can check your own application, under authorisation, and confirm that your defences hold. The test cases help you verify that your application cannot be tricked into reading or including files outside its intended directory.

Why this vulnerability matters

Path traversal and local file inclusion occur when an application uses user input to build a file path without restriction, letting input reference files outside the intended location. It can expose sensitive files. It appears in the OWASP Top Ten precisely because it is common and serious, which is why testing for it against your own applications, and understanding how it works, is essential to defending against it.

The defence, and responsible use

The defence is to never build file paths from raw user input, to validate against an allowlist of permitted files, and to resolve and check the final path stays within the intended directory. Testing confirms the restriction holds. This tool is for authorised security testing of systems you own or have explicit permission to test, for security research, and for education, testing without authorisation is illegal and unethical. It runs entirely in your browser, so nothing you enter is uploaded.

Related tools

  • User Agent Parser — Parse a User-Agent string into browser, engine, operating system and device. Explains why UA strings are unreliable and what to use instead.
  • QR Code Generator — Generate QR codes for URLs, text, Wi-Fi and contact details. Adjustable error correction and size, produced entirely in your browser.
  • Credit Card Validator — Validate a card number with the Luhn algorithm and identify the issuing network from its prefix. Runs locally, nothing is transmitted.
  • Text Case Converter — Convert text between camelCase, PascalCase, snake_case, kebab-case, CONSTANT_CASE, Title Case and sentence case. Runs entirely in your browser.

Frequently Asked Questions

How do I prevent path traversal?

By never building file paths from raw user input, validating against an allowlist, and confirming the resolved path stays within the intended directory.

What does the test verify?

That your application cannot be induced to read or include files outside its intended directory, confirming your path handling is safe.

Is this for attacking other people’s systems?

No. It is for authorised testing of systems you own or have explicit permission to test, and for security education. Unauthorised testing is illegal.

Is my input uploaded?

No. It runs entirely in your browser.

Privacy & Security

Processed locally.

Data: None
Client-side-Side
Active
v1.0

About This Tool

This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.