We covered the solution for C0m80 Vulnhub where we demonstrated the exploitation of Mantis bug tracker web application and at the end escalated privileges on the Linux system using reverse engineering.

Mantis Bug Tracker is an open source issue tracker that provides a delicate balance between simplicity and power. Users are able to get started in minutes and start managing their projects while collaborating with their teammates and clients effectively. Once you start using it, you will never go back!

We used this exploit “Mantis Bug Tracker 2.3.0 – Remote Code Execution (Unauthenticated)”

We also demonstrated port tunneling in this challenge to access the internal port 65122 which was not visible during the first initial nmap scan.

Get OSCP Certificate Notes

The Complete Practical Web Application Penetration Testing Course

About the Author

Mastermind Study Notes is a group of talented authors and writers who are experienced and well-versed across different fields. The group is led by, Motasem Hamdan, who is a Cybersecurity content creator and YouTuber.

View Articles