Web Application Exploitation | EP1 | C0m80 Vulnhub CTF challenge

Motasem Hamdan
1 min readMar 5, 2024

--

We covered the solution for C0m80 Vulnhub where we demonstrated the exploitation of Mantis bug tracker web application and at the end escalated privileges on the Linux system using reverse engineering.

Mantis Bug Tracker is an open source issue tracker that provides a delicate balance between simplicity and power. Users are able to get started in minutes and start managing their projects while collaborating with their teammates and clients effectively. Once you start using it, you will never go back!

We used this exploit “Mantis Bug Tracker 2.3.0 — Remote Code Execution (Unauthenticated)”

We also demonstrated port tunneling in this challenge to access the internal port 65122 which was not visible during the first initial nmap scan.

Video Walkthrough

--

--

Motasem Hamdan
Motasem Hamdan

Written by Motasem Hamdan

Motasem Hamdan is a content creator and swimmer who creates cyber security training videos and articles. https://www.youtube.com/@MotasemHamdan

No responses yet