Before we begin I would like to stay it took me more than 3 hours to figure out how to do privilege escalation. Don’t criticize I’m a noob. so now lets start with nmap. Auturecon for some unknown reason didn’t run gobuster. So in the end decided to run dirbuster which is a also another very cool tool
data:image/s3,"s3://crabby-images/e011c/e011cd72ab3253fe5d318b4c28f96191eaa3f40a" alt=""
Alright so after seeing the great and wise IIS had to have look at what its hosting.
data:image/s3,"s3://crabby-images/f7e2e/f7e2eb1b39e7784022bea1961335f44084f3ebef" alt=""
Merlins beard. So we found merlin. let’s try to kill him and the only way to do it would be to become a warlock. Time to bruteforce merlin
data:image/s3,"s3://crabby-images/6f8e5/6f8e5bc07256ee38ece93e2baa5478b5216055b3" alt=""
There was no name but opened in browser
data:image/s3,"s3://crabby-images/5993b/5993bb49914dcd1d0284049305c8b2533b7c1b4e" alt=""
ok so after checking which extensions are allowed and also found an rce. you can read about it from this link
And also need a powershell script to execute a shell. You can get it from here
https://gist.github.com/egre55/c058744a4240af6515eb32b2d33fbed3
I think you will get the idea once you read those two links if not here is a screenshot
So now upload the web.config file. Successss! we got a shell
data:image/s3,"s3://crabby-images/91c6a/91c6a64fb29ce253ec6975dec558dce9d165b42c" alt=""
Now the hard part. Privilege escalation. Got the systeminfo tried windows exploit suggester. Tried a lot of things which didn’t work or Im too dump to make it work.
data:image/s3,"s3://crabby-images/29e88/29e888e75b7f6b8393286263223de49652091a4a" alt=""
So in the end this kernel exploit worked. As you can see I have uploaded there quite a bit of exploit’s from here and there. But I need to remember something. I’m pretty sure that there isn’t any kernel exploits in the OSCP exam. So I will try to find some other ways starting from now. But in case I get lazy, Yes I will go after the kernel exploit.
data:image/s3,"s3://crabby-images/7b583/7b583836a3c1ee38852b2ac72e007feda0ab042a" alt=""
Be First to Comment