mKingdom
Beginner-friendly box inspired by a certain mustache man.
Last updated
Beginner-friendly box inspired by a certain mustache man.
Last updated
We can see that we get a login page : /app/castle/index.php/login
With a lot of tries we can get the access to the admin panel :
We can test the RCE like this :
Add php file to allowed file types :
Create a reverse php file :
And you can test the RCE on the FileManager :
We are www-data. So we search for user.txt and root.txt files and we can get the flags ;)
This is a concrete5 website. We can get the version with :
With some research we get this RCE with the version :
If you want a cool extension to get quickly some reverse shell or others payloads this is a great tool :