SECOND MACHINE
SECOND
Once the host was identified, scanning tool, was used to discover which services were running on the machine. The scan revealed a webpage which you can see in the picture below.
Now we are going to create a username but we can see in the column display name (Administrator' --) in the picture below.
As we have created the username we have introduce the credentials:
Username pepe
Password pepe123
Here we are stay in control panel of user Pepe as you can see below.
If we go to settings, we will be able to change the password and as we have discovered there is sql inyection two phases the same password to Pepe is for root Administrator.
Gotha! as you can see below we are Administrator and we have found out the flag which you can see in the picture below.
Thank you very much for reading this article
I hope you liked and learned something new
This article has been done with ethical proposes
Good Hack
Comments
Post a Comment