System Recognition (Windows)
Optimum - Hack The Box
La máquina Optimum, bastante sencilla con varias formas para poder vulnerarla, en mi caso use el CVE-2014-6287 para poder acceder a la máquina como usuario, y para escalar privilegios utilice el …
WindowsHttp File Server (HFS)Remote Command Execution (RCE)CVE-2014-6287 (RCE)System Recognition (Windows)Local Privilege Escalation (LPE)Privesc - MS16-098 (LPE)Privesc - MS16-032 (LPE)OSCP StyleMetasploit Framework
Devel - Hack The Box
Una máquina bastante sencilla, en la cual usaremos el servicio FTP para cargar un Payload que contendrá una Shell que se activará en el puerto HTTP que corre el servicio IIS y después escalaremos …
WindowsMicrosoft IISFTPFTP EnumerationAbusing FTP ServiceLocal File Inclusion (LFI)Reverse ShellAbusing IIS ServiceASPX WebShellSystem Recognition (Windows)Local Privilege Escalation (LPE)Privesc - MS11-046 (LPE)Privesc - MS13-053 (LPE)OSCP StyleMetasploit Framework

