Local Privilege Escalation (LPE)

24 February 2025 · TheHackerLabs, Medium Machine

Pacharan - TheHackerLabs

Esta fue una máquina algo complicada. Después de analizar los escaneos, descubrimos que estamos ante un Active Directory (AD) y asumimos que no podemos hacer nada más que comenzar a enumerar usuarios …

WindowsActive DirectoryKerberosSMBRPCKerberos EnumerationSMB EnumerationRPC EnumerationLocal Privilege Escalation (LPE)System Recognition (Windows)Abusing SeLoadDriverPrivilege PrivilegeCVE-2024-35250 (LPE)Privesc - Abusing SeLoadDriverPrivilege PrivilegePrivesc - CVE-2024-35250 (LPE)OSCP StyleMetasploit Framework
Pacharan - TheHackerLabs
22 May 2023 · HackTheBox, Easy Machine

Driver - Hack The Box

Es una máquina relativamente sencilla, comenzamos entrando al servicio HTTP, el cual nos pedirá credenciales para poder entrar, adivinamos las credenciales y enumerando el sitio web, encontramos que …

WindowsSMBMFP Firmware UploadSCF Malicious FileCracking HashSystem Recognition (Windows)Local Privilege Escalation (LPE)Abusing Vuln Process SpoolsvPrivesc - PrintNightmare Exploit (CVE-2021-1675)OSCP Style
Driver - Hack The Box
7 March 2023 · HackTheBox, Easy Machine

Shocker - Hack The Box

Esta fue una máquina algo compleja porque tuve que investigar bastante, pues al hacer los escaneos no mostraba nada que me pudiera ayudar. Sin embargo, gracias al Fuzzing pude encontrar una línea de …

LinuxShellShock AttackFuzzingRemote Code Execution (RCE)Reverse ShellAbusing Sudoers PrivilegesPrivesc - Abusing Sudoers PrivilegesLocal Privilege Escalation (LPE)System Recognition (Linux)Remote Command Injection (RCI)CVE-2014-6278 (RCI)CVE-2014-6271 (RCI)BurpSuitePwnkit Pkexec Exploit (LPE)Privesc - CVE-2021-4034 (Pwnkit Pkexec Exploit)OSCP StyleMetasploit Framework
Shocker - Hack The Box
19 February 2023 · HackTheBox, Easy Machine

Bank - Hack The Box

Esta máquina fue algo difícil porque no pude escalar privilegios usando un Exploit sino que se usa un binario que automáticamente te convierte en Root, además de que tuve que investigar bastante sobre …

LinuxApache httpd 2.4.7Domain Zone Transfer Zone Attack (AXFR)Virtual HostingFuzzingInformation LeakageRemote Command Execution (RCE)Reverse ShellLocal Privilege Escalation (LPE)Privesc - Abusing SUID Binary (LPE)OSCP StyleMetasploit Framework
Bank - Hack The Box
18 February 2023 · HackTheBox, Easy Machine

Grandpa - Hack The Box

Esta fue una máquina fácil en la cual vamos a vulnerar el servicio HTTP del puerto 80 que está usando Microsoft IIS 6.0 WebDAV, usando un Exploit que nos conectara de forma remota a la máquina …

WindowsIIS 6.0 WebDAVRemote Buffer Overflow (RBO)CVE-2017-7269 (RBO)System Recognition (Windows)Local Privilege Escalation (LPE)Privesc - Churrasco Token Kidnapping (LPE)Reverse ShellOSCP Style
Grandpa - Hack The Box
17 February 2023 · HackTheBox, Easy Machine

Arctic - Hack The Box

Una máquina algo sencilla, vamos a vulnerar el servicio Adobe ColdFusion 8 usando el Exploit CVE-2009-2264 que nos conectara directamente a la máquina usando una Reverse Shell, entraremos como usuario …

WindowsFTMPAdobe ColdFusionRemote Command Execution (RCE)CVE-2009-2265 (RCE)Reverse ShellSystem Recognition (Windows)Local Privilege Escalation (LPE)Privesc - MS10-059 (LPE)OSCP Style
Arctic - Hack The Box
16 February 2023 · HackTheBox, Easy Machine

Optimum - Hack The Box

La máquina Optimum, bastante sencilla con varias formas para poder vulnerarla, en mi caso use el CVE-2014-6287 para poder acceder a la máquina como usuario, y para escalar privilegios utilice el …

WindowsHttp File Server (HFS)Remote Command Execution (RCE)CVE-2014-6287 (RCE)System Recognition (Windows)Local Privilege Escalation (LPE)Privesc - MS16-098 (LPE)Privesc - MS16-032 (LPE)OSCP StyleMetasploit Framework
Optimum - Hack The Box
14 February 2023 · HackTheBox, Easy Machine

Devel - Hack The Box

Una máquina bastante sencilla, en la cual usaremos el servicio FTP para cargar un Payload que contendrá una Shell que se activará en el puerto HTTP que corre el servicio IIS y después escalaremos …

WindowsMicrosoft IISFTPFTP EnumerationAbusing FTP ServiceLocal File Inclusion (LFI)Reverse ShellAbusing IIS ServiceASPX WebShellSystem Recognition (Windows)Local Privilege Escalation (LPE)Privesc - MS11-046 (LPE)Privesc - MS13-053 (LPE)OSCP StyleMetasploit Framework
Devel - Hack The Box