基本信息
data:image/s3,"s3://crabby-images/de3f4/de3f46477dbfceffbd50364083042865a96ef677" alt=""
端口扫描
就一个80:
1 | nmap -sC -sV 10.10.10.14 |
80
IIS 6.0,默认建设中页面:
data:image/s3,"s3://crabby-images/8ec95/8ec953e23e7f38fa445c8d54602742c827992d99" alt=""
#CVE-2017-7269
搜索得到:
- Microsoft IIS 6.0 - WebDAV ‘ScStoragePathFromUrl’ Remote Buffer Overflow - Windows remote Exploit
https://www.exploit-db.com/exploits/41738
msf有模块直接一键打,拿到的是network service权限shel(因为是BOF,很容易把服务打挂,显示错误就reset机器吧)l:
data:image/s3,"s3://crabby-images/a9b1a/a9b1ae2e64d5eccdedc72a8aa3f3ce732b98afac" alt=""
提权信息
然后直接用local_exploit_suggester:
data:image/s3,"s3://crabby-images/17413/17413e923d20aa21fe74a69e301c3dd30f625a4f" alt=""
提权
随便选一个,打就完事了,打之前需要mighrate到一个标准进程:
data:image/s3,"s3://crabby-images/ab983/ab98333d11dab2ea52bd62ea6819dccfb20df26e" alt=""
打完之后我们的service shell就变成system了:
data:image/s3,"s3://crabby-images/720e2/720e23625cd8df63fc66532c83c00badf1751504" alt=""
flags
然后直接去读取flag:
1 | meterpreter > search -f user.txt |
data:image/s3,"s3://crabby-images/24555/245554f2cbfb840d0d5e78bde4b588f9121e01cf" alt=""
参考资料
- Microsoft IIS 6.0 - WebDAV ‘ScStoragePathFromUrl’ Remote Buffer Overflow - Windows remote Exploit
https://www.exploit-db.com/exploits/41738 - HTB: Grandpa | 0xdf hacks stuff
https://0xdf.gitlab.io/2020/05/28/htb-grandpa.html#shell-as-network-service - https://www.hackthebox.eu/home/machines/writeup/13
- HackTheBox - Granny and Grandpa - YouTube
https://www.youtube.com/watch?v=ZfPVGJGkORQ&feature=youtu.be&ab_channel=IppSec