↓Skip to main content

SQLMAP

OFFSEC - Proving Grounds - CARRYOVER
·3043 words·15 mins
OFFSEC PG PRACTICE SQLMAP LD_PRELOAD
Carvilla on port 80 is vulnerable to SQL injection, providing initial access via SQLmap. An exposed LD_PRELOAD variable enables a custom shared object to be executed with sudo, escalating privileges to root.
OFFSEC - Proving Grounds - NULLBYTE
·2634 words·13 mins
OFFSEC PG PRACTICE EXIFTOOL HYDRA SQLMAP DIRTYCOW CVE-2016-5195
Exiftool reveals a hidden directory. Hydra bypasses the key, SQL injection dumps a hash, which is cracked for SSH access. DirtyCow (CVE-2016-5195) is exploited to gain root.
OFFSEC - Proving Grounds - GROOVE
·1418 words·7 mins
OFFSEC PG PRACTICE CHURCHCRM SQLMAP HASHCAT
ChurchCRM 4.5.1 on port 80 has weak credentials. Using an SQL injection via sqlmap reveals the root hash. Cracking it grants root access.
OFFSEC - Proving Grounds - SILICON
·1560 words·8 mins
OFFSEC PG PRACTICE SQLMAP
KORTEX ADVOCATED software on port 8000 which has SQLi vulnerability (CVE-2024-7640). Dump and crack hashes for initial access, escalate to root via ruby3.1.
OFFSEC - Proving Grounds - WORKAHOLIC
·2806 words·14 mins
OFFSEC PG PRACTICE WPPROBE SQLMAP HASHCAT FTP STRACE GCC
Use OFFSEC creds or scan Wordpress. Exploit a Wordpress vulnerability (CVE-2024-9796), crack hashes for charlie/ted. FTP as ted and SSH in as charlie. Escalate to root via SUID binary with custom shared object.