# prog2 Shell Vectors — FINAL
# Date: 2026-09-23

## COMPLETE BLOCKERS FOR SHELL ON prog2

### Root Cause: MySQL (uid 996) ≠ Apache (uid 48)

| Layer | MySQL can write? | Apache can read? |
|-------|-----------------|-----------------|
| /var/www/html/ | ❌ Permission denied (uid 996) | ✅ |
| /tmp/ | ✅ (0660 mysql:mysql) | ❌ (uid 48) |
| /var/tmp/ | ✅ (0660 mysql:mysql) | ❌ (uid 48) |
| /var/lib/mysql/ | ✅ (0660 mysql:mysql) | ❌ (uid 48) |
| /dev/shm/ | ❌ Permission denied | — |
| /var/lib/php/session/ | ❌ Permission denied | ✅ (Apache owns) |
| /var/www/html/wp-content/uploads/ | ❌ No such file (MySQL) | ✅ (read-only) |

### Shell Vectors Attempted

| Vector | Result | Blocker |
|--------|--------|---------|
| MySQL INTO OUTFILE → webroot | ❌ | Permission denied |
| MySQL INTO OUTFILE → /tmp + LFI | ❌ | No LFI in PHP files |
| Session poisoning (/tmp/sess_*) | ❌ | PHP session_decode ≠ eval |
| Theme path traversal (MySQL → /tmp + WP option) | ❌ | Apache can't read MySQL files (0660) |
| Plugin upload via WP admin | ❌ | wp-content/uploads not writable |
| Media upload (GIF with PHP) | ❌ | Same — uploads dir read-only |
| .htaccess upload | ❌ | belajarUpload.php is stub |
| CVE-2024-4577 (PHP CGI) | ❌ | mod_php, not CGI |
| CVE-2021-41773 (Apache path traversal) | ❌ | Affects 2.4.49/50, not 2.4.6 |
| PHP 5.6 NULL byte injection | ❌ | No LFI vectors |
| general_log redirect | ❌ | Can't set to webroot path |
| UDF sys_exec | ❌ | plugin_dir read-only |
| Replication SSRF | ❌ | Outbound firewall |

### What We DID Achieve (without shell)

1. WordPress admin access (temporary, via MD5 hash in DB)
2. WordPress 4.9.15 + 10 plugins identified
3. All WordPress data exfiltrated (users, options, sessions, media)
4. vitropic.co.id confirmed live on prog2
5. 150+ PHP source files exposed (directory listing)
6. 29,370 ID documents (KTP/NPWP/SIA/SIPA) in directory listing
7. Stored procedures secrets (Kredivo, Payment Gateway, Shopee, Lazada)
8. GitLab public repos with MySQL creds
9. MSSQL passphrase "Jaya terus PT Pharos Indonesia!"

### CONCLUSION

Shell on prog2 is NOT achievable through any known vector.
The host is protected by:
- Read-only filesystem on /etc, /root, /home, /boot
- File permission isolation between MySQL (uid 996) and Apache (uid 48)
- No LFI in any PHP file
- No CGI/FPM (mod_php only)
- Outbound firewall (no SSRF)
- fail2ban on SSH
- Apache 2.4.6 (too old for path traversal CVEs)
