Netmon
Easy box from HTB, quite frankly user flag could have been hidden a bit more. Enumerating the server to obtain the bak files was quite a challenge. RCE at the end was basic
Learning:
Enumeration on FTP
Credential Hunt
Executing RCE manually or using msfconsole
Enumeration
Check ftp
User.txt lives can be found on Public user when you navigate through the FTP
Enumerating ftp to obtain user credentials:
Goal attempt to find old bak files
Find old config files
Users:
Bruteforce Attempt - Did not work
Navigating on FTP again looking for credential:
User Credential Found:
RCE
Another way obtaining RCE
In the PRTG Admin Panel head to:
Setup
Account Settings
Notifications
Inside the Notification setting head to Execute Program
In the parameter Key input the Rev-Shell
Make sure you select
Demo exe notification - outfile.ps1
in the Program File parameterSave
Create netcat session `nc -lvnp 1234`
Ones uploaded Head to notifications
Click our created notification name
pwn
On the far right hand side you will see a small box with a pen click that
Click the bell (if you hover on it it will say send notification)
RCE done!
Popped it.
Last updated