AuthBy
Enumeration
There is an information disclosure at accounts directory.
acc[Offsec].uac
acc[anonymous].uac
acc[admin].uac
There is a .htpasswd file.
Initial Access
We need to put cmd.php command shell to admin's ftp directory. Because this directory is a web directory at 242/tcp port.
Web credential - offsec:[REDACTED]
You can use smbserver.py to get reverse shell with nc.exe.
smbserver.py - https://github.com/SecureAuthCorp/impacket/blob/master/impacket/smbserver.py
nc.exe - https://github.com/int0x33/nc.exe
PrivEsc
SeImpersonatePrivilege - Enabled
http://ohpe.it/juicy-potato/ http://ohpe.it/juicy-potato/CLSID
https://github.com/ivanitlearning/Juicy-Potato-x86/releases/download/1.2/Juicy.Potato.x86.exe
We need to put Juicy.Potato.x86.exe and nc.exe to admin's ftp directory.
Windows Server 2008 R2 Enterprise CLSID
Last updated