Hack the box Optimum is a Windows based easy machine. Initial foothold was using fileserver exploit. Privilege escalation using kernel exploit. Starting with Nmap
data:image/s3,"s3://crabby-images/38c16/38c16a14b0951df8aea9378be9c7d180ab1006d5" alt=""
Port 80 was the only port which was open. Site contains HTTPFileServer.
data:image/s3,"s3://crabby-images/29e29/29e29272387cb721f673a88f1f225d37d70054a7" alt=""
Googled a bit found an exploit. Wasn’t really that hard. Can download the exploit from the link below.
https://www.exploit-db.com/exploits/39161
data:image/s3,"s3://crabby-images/702a6/702a698be295e8f3d53c8570a9997e1e052c9463" alt=""
We need netcat hosted in a webserver and and the rest it easy but first change the script.
data:image/s3,"s3://crabby-images/27a4d/27a4d472128de64ac1233d8e84fb3ae887737fe3" alt=""
We need to setup the stage to execute the show.
data:image/s3,"s3://crabby-images/258e4/258e47a42e54006094590bc67bd0fe27e052d35b" alt=""
Had to run the exploit twice to get it working. Got the user flag, now what’s left is privilege escalation.
data:image/s3,"s3://crabby-images/3ea63/3ea634d376e788560307fe37b9606a1ed3b93d55" alt=""
Nothing interesting let’s check few more things
data:image/s3,"s3://crabby-images/65001/650016b74885986ede6f678a308032c46c56c61c" alt=""
Ran winpeas to check and the only thing that came up was password of kostas.
data:image/s3,"s3://crabby-images/83799/837997f81fc8dce93ec1df86ecfa1e0b75477b78" alt=""
Found a kernel exploit. I guess will just do it this time. Download the exploit from the following link.
https://github.com/offensive-security/exploitdb-bin-sploits/raw/master/bin-sploits/41020.exe
data:image/s3,"s3://crabby-images/12ace/12ace81e516826a035bbabe78c8c836317c0f31b" alt=""
Got the root flag.
You can follow me on twitter to get the latest updates https://twitter.com/far3y
Be First to Comment