Header Banner
Null Byte Logo
Null Byte
wonderhowto.mark.png
Cyber Weapons Lab Forum Metasploit Basics Facebook Hacks Password Cracking Top Wi-Fi Adapters Wi-Fi Hacking Linux Basics Mr. Robot Hacks Hack Like a Pro Forensics Recon Social Engineering Networking Basics Antivirus Evasion Spy Tactics MitM Advice from a Hacker

How to Hack Hackademic.RTB1 Machine Part 1

Dec 30, 2015 06:32 AM
Command line output displaying network configuration and connection details.

Welcome hackers.

Hackacademic.RTB1 is vulnerable machine for training our skills.This machine can be download from free from here. There is many tutorial how to hack these machine but i did always be my self.

Recognize Open Ports

First step is recognize open ports in machine.We can use our favourite nmap scanner and just simply type nmap

Command line interface displaying network information and packet statistics.

I use T4 option in mnap for just simple do faster scan :)As we can see there are just 1 open port and there is port 80.

So we do some digging and start our browser and insert ip address of out machine.

How to Hack Hackademic.RTB1 Machine Part 1

So our victim page looks like this one after some clicking and looking for url you can see some possibilities of SQL injection. After insert ' at the end of url.We get error of SQL.Huray!! We immediately start our second most powerful program

How to Hack Hackademic.RTB1 Machine Part 1

SQL Injection

In this section we just can start sqlmap program and check if our link is really vulnerable.So we simple run sqlmap.py -u "" --dbs

after runnig couple more programs we are able to retrieve wordpress user.Sorry guys I don't want to show you all steps :) Just try to figure out how many other sqlmap you have to run to get all users and theirs passwords.When you check carefully tables of user we can see that open user has priority 10 which means that user is admin and have highest privileges in wordpress. We just simpe type

Code snippet displaying structured data in a terminal format.

after these we can simple login.

Just insert into browser HackademicRTB1/wp-admin/

We should see login page for wordpress and just simple insert credential

Login screen for WordPress with username and password fields.

So I really want these make as one tutorial but for me it's too late and i heading to bed.Second part soon :) If you have any question ale any feedback please let me known :)

Cheers Spyx

You already know how to use your phone. With Gadget Hacks' newsletter, we'll show you how to master it. Each week, we explore features, hidden tools, and advanced settings that give you more control over iOS and Android than most users even know exists.

Sign up for Gadget Hacks Weekly and start unlocking your phone's full potential.

Related Articles

Comments

No Comments Exist

Be the first, drop a comment!