Decided to do a windows box after a while. Chatterbox is Medium level Windows box. Let’s start with Nmap
data:image/s3,"s3://crabby-images/9f94a/9f94aeae86da2cf36dc8fd7ee195fddb093b4408" alt=""
We can see port 9255 and 9256 but we don’t know which service it’s running. let’s enumerate a bit more
data:image/s3,"s3://crabby-images/5ed45/5ed45d044e0156fecde2d70ab13e04059763a861" alt=""
let’s search for an exploit using searchsploit
data:image/s3,"s3://crabby-images/2d86a/2d86a0dcda0336327ab3f89b6549231a98f2c41a" alt=""
we found an exploit. Let’s check how it works.
data:image/s3,"s3://crabby-images/71dac/71dac0fa42ef02002527d2c417246abad461ee0f" alt=""
It’s a buffer overflow exploit. It’s popping up calculator. Have to remember that maybe we can take advantage of that but right now we need a reverse shell not to pop a calculator. let’s change the msfvenom to get a reverse shell.
data:image/s3,"s3://crabby-images/55686/5568689d8a803901fd96394b9e8bad45616b27b0" alt=""
We need to edit the script with the new shellcode and one more thing, change the attacking server IP.
data:image/s3,"s3://crabby-images/babb7/babb7123c237b303a82636106bc7de0a3fee067e" alt=""
Everything is set. Netcat is already listening to port 4444. Time to fire the payload.
data:image/s3,"s3://crabby-images/4e85f/4e85f28520dd1b04d95337fdf62fd01065395252" alt=""
Poof, just like that we got a shell. We need to check the privileges
data:image/s3,"s3://crabby-images/96137/96137dd83627b5c4b080035d5bb5c629b4fef063" alt=""
Don’t see any other way to get privilege escalation. lets use the cacls one.
data:image/s3,"s3://crabby-images/52079/52079b10679fe83249fc19c0dee116bd98f217b4" alt=""
Gave alfred rights to read the file. If you liked what I have written consider to spread the knowledge and also follow me on twitter https://twitter.com/far3y
Be First to Comment