Grandpa
Last updated
Was this helpful?
Last updated
Was this helpful?
HTB 9. Grandpa
nmap -T4 -A -p- 10.10.10.14
shows 80 open with version Microsoft IIS httpd 6.0
(dated version) and poentially risky methods (TRACE
and `PUT)
Go to 10.10.10.14
shows "Under Construction" page.
Google Microsoft IIS httpd 6.0 exploit
finds and .
searchsploit ScStoragePathFromUrl
shows python and ruby modules.
Metasploit
Try running again (4 times)
We are not system. ps
to show processes. Pick a process that has NT AUTHORITY\NETWORK SERVICE
with migrate 1788
and success.
Priv esc suggester:
Result: 9 options, go down list and try to see what works
start with ms10_015_kitrap0d
and set lhost tun0
getuid
is NT AUTHORITY\SYSTEM
.