Hackthebox - Optimum
Contents
From nmap, only port 80 is opened.
It is the web page.
There is an exploit for HttpFileServer 2.3
. I use module windows/http/rejetto_hfs_exec
in msf, and get the user OPTIMUM\kostas
.
Later, I use module multi/recon/local_exploit_suggester
, and tried module windows/local/ms16_032_secondary_logon_handle_privesc
from the previous result.
And we are now NT AUTHORITY\SYSTEM
.
Author L3o
LastMod 2020-05-11