Granny HTB
IP
initial nmap scan
Looks like we have one port open on the machine
80
Lets get enumerate further and see if we can find any other details
results
We can see
Running Microsoft IIS httpd 6.0 (pretty outdated)
webdav is enabled
This does look very familiar to the grandpa box we have solved recently meaning i can try the same explaoit and gain a shell on the system
Lets start a listner
lets run the exploit script
Looking back at our listener we can see we have a shell on the target
Since we know that the grandpa box was vulnerable to token manipulation good chances we have the same scenario here lets check
Looks like it so Lets upload
nc.exe
churrasco.exe
start an smb server and transfer all the files across
copy the files across to the target machine
start a listener
run the exploits
Now if we look back at our listner we should see we have a shell as nt authority\system
Last updated