Summary
Servmon,a Windows box created by HackTheBox user dmw0ng.Initially scan show us that ftp is running with anonymous login.Checking those we find some hints for a file Passwords.txt
on Nathan
Desktop.Checking Web
we find it is running NVMS-1000
checking searchsploit
we see it have Directory Traversal
using which we can read the passwords.txt
file.
Using crackmapexec
we can try all the passwords and against Nathan
and Nadine
and we get a valid credential for Nadine
. Using that we can ssh
to the box and we have user on this box.Privilege Escalation on this was fun we need to exploit NSClient++
RCE to get a nt authority/ system
shell.