How to Hack Hackademic.RTB1 Machine Part 1

Dec 30, 2015 06:32 AM
635870239491584678.jpg

Welcome hackers.

Hackacademic.RTB1 is vulnerable machine for training our skills.This machine can be download from free from here. There is many tutorial how to hack these machine but i did always be my self.

Step 1: Recognize Open Ports

First step is recognize open ports in machine.We can use our favourite nmap scanner and just simply type nmap

635870239491584678.jpg

I use T4 option in mnap for just simple do faster scan :)As we can see there are just 1 open port and there is port 80.

So we do some digging and start our browser and insert ip address of out machine.

635870242017485889.jpg

So our victim page looks like this one after some clicking and looking for url you can see some possibilities of SQL injection. After insert ' at the end of url.We get error of SQL.Huray!! We immediately start our second most powerful program

635870244753632494.jpg

Step 2: SQL Injection

In this section we just can start sqlmap program and check if our link is really vulnerable.So we simple run sqlmap.py -u "" --dbs

after runnig couple more programs we are able to retrieve wordpress user.Sorry guys I don't want to show you all steps :) Just try to figure out how many other sqlmap you have to run to get all users and theirs passwords.When you check carefully tables of user we can see that open user has priority 10 which means that user is admin and have highest privileges in wordpress. We just simpe type

635870248785283148.jpg

after these we can simple login.

Just insert into browser HackademicRTB1/wp-admin/

We should see login page for wordpress and just simple insert credential

635870250364475956.jpg

So I really want these make as one tutorial but for me it's too late and i heading to bed.Second part soon :) If you have any question ale any feedback please let me known :)

Cheers Spyx

Comments

No Comments Exist

Be the first, drop a comment!