Sign inSign up

filipkarc/sqli-postgres-rce-privesc-hacking-playground

By filipkarc

•Updated about 1 year ago

Intentionally vulnerable web application: SQL Injection + RCE + Privilege Escalation

Image
0

2.8K

filipkarc/sqli-postgres-rce-privesc-hacking-playground repository overview

This image only runs on x86-64 systems, not on ARM (like Apple Silicon).

⁠Vulnerable Web App: sqli-postgres-rce-privesc-hacking-playground

image

⁠What is it

This is free vulnerable app for pentesters / cybersecurity students / developers to experiment with SQL Injection vulnerability and privilege escalation.

You will find a detailed description here: https://www.karczewski.io/blog/intentionally-vulnerable-web-application-sql-injection-rce-privilege-escalation/⁠

Recommended path:

1. exploit the SQLi vulnerability
2. get shell via vulnerable version of PostgreSQL
3. perform privilage escalation and become root

Have fun :)

⁠How to run

docker run -p 8091:80 -d filipkarc/sqli-postgres-rce-privesc-hacking-playground

Then launch your browser and enter http://localhost:8091⁠

⁠WARNING !!! Read this:

This application is intentionally INSECURE and is meant solely for demonstrating security risks in a controlled environment. It should never be exposed to public networks or production systems. Running this application outside of isolated labs may result in unauthorized access or system compromise. Usage is at the user's own risk.

⁠Follow me

LinkedIn: https://www.linkedin.com/in/filip-karczewski/⁠

Twitter: https://twitter.com/karczewski_io⁠

⁠Thank you

Thanks to the creator of the photo I used:

https://www.pexels.com/photo/cute-puppy-wearing-a-party-hat-4588047/⁠

Tag summary

Content type

Image

Digest

sha256:80f5879ba…

Size

145.8 MB

Last updated

about 1 year ago

docker pull filipkarc/sqli-postgres-rce-privesc-hacking-playground