Use the LFI vuln to identify users. Either find the web apps config file that holds user/pass data or grab the etc/passwd file.

-We can possibly find the /etc/knockd.conf file and see if there is a sequence of ports we can knock in order to unlock/open a new port. If we can knock, re-scan with nmap to see the new port open. This technique is called ‘Port Knocking’

script to port knock