Grandpa
HTB 9. Grandpa
nmap -T4 -A -p- 10.10.10.14
shows 80 open with versionMicrosoft IIS httpd 6.0
(dated version) and poentially risky methods (TRACE
and `PUT)Go to
10.10.10.14
shows "Under Construction" page.Google
Microsoft IIS httpd 6.0 exploit
finds Microsoft IIS 6.0 - WebDAV 'ScStoragePathFromUrl' Remote Buffer Overflow and Rapid7.searchsploit ScStoragePathFromUrl
shows python and ruby modules.Metasploit
Try running again (4 times)
We are not system.
ps
to show processes. Pick a process that hasNT AUTHORITY\NETWORK SERVICE
withmigrate 1788
and success.Priv esc suggester:
Result: 9 options, go down list and try to see what works
start with
ms10_015_kitrap0d
andset lhost tun0
getuid
isNT AUTHORITY\SYSTEM
.
Last updated