Attack Defence: Windows Basic Exploitation #4
data:image/s3,"s3://crabby-images/30664/306646de88327455d1babe328b7cec2e685bce58" alt="Attack Defence: Windows Basic Exploitation #4"
Hello everyone, I have returned to tackle part four of my series on Windows exploitation, in this episode you will learn how to exploit Process Builder utility to gain access to windows environment.
I recommend you to first try out this lab on Attack Defence => https://www.attackdefense.com/challengedetails?cid=1947
As usual, we will start with info gathering.
Reconnaissance
Using nmap to get open ports
nmap --top-ports 50000 10.5.27.126
As expected, HTTP Port 80 is open and Process Builder is being served
data:image/s3,"s3://crabby-images/5612d/5612d62f0c6a5d9f5887bb37f58039af6b1a84d8" alt=""
Also we are provided with the login credentials admin:password
Exploitation
If you have read my last post Windows Basic Exploitation #3. You know what the exploit is. In this I will simply execute it to retrieve the flag
data:image/s3,"s3://crabby-images/db1ec/db1ec728ae293b020e3bfe261b4e49cf5ed13539" alt=""
You can then find the flag in C:\flag.txt
You can connect me on the following platforms
- Twitter: @tbhaxor
- GitHub: @tbhaxor
- LinkedIn: @gurkirat--singh
- Instagram: @tbhaxor
data:image/s3,"s3://crabby-images/879c5/879c5a805ff12c9561178a6d99903456d276c8fa" alt=""