Devel
Got root using MS10-015 kernel exploit after failing all Potato/UAC bypass attempts.
Summary
🧵 Let's Unpack
🔍Enumeration
sudo nmap -sC -sV -A -T4 -p- 10.10.10.5PORT STATE SERVICE VERSION
21/tcp open ftp Microsoft ftpd
| ftp-anon: Anonymous FTP login allowed (FTP code 230)
| Files listed: aspnet_client, iisstart.htm, shelly.asp, shelly.aspx, welcome.png
| ftp-syst:
| SYST: Windows_NT
80/tcp open http Microsoft IIS httpd 7.5
| http-title: IIS7
| http-server-header: Microsoft-IIS/7.5
| http-methods:
| Potentially risky methods: TRACE️️⚙ Initial Foothold
Privilege Escalation
Last updated