💣
Proving Grounds Writeups
  • kashz PG Writeups
  • PG boxes
    • ALGERNON
      • 4 :9998 IIS 10
      • 3 :80 IIS 10
      • 2 :21 ftp
      • 1 recon
    • APEX
      • 9 privesc
      • 8 box enum www-data
      • 7 :80 openemr exploit
      • 6 :3306 mysql
      • 5 :80 /filemanager 9.13.4
      • 4 :80 openemr
      • 3 :80 apex hospital
      • 2 :445 smb
      • 1 recon
    • AUTHBY
      • 6 privesc
      • 5 box enum apache
      • 4 :21 ftp admin
      • 3 :242 apache
      • 2 :21 ftp
      • 1 recon
    • BANZAI
      • 9 post enum
      • 8 mysql > privesc > root
      • 7 apache enum
      • 6 box enum www-data
      • 5 :8295 banzai
      • 4 :25 smtp
      • 3 :5432
      • 2 :21 ftp
      • 1 recon
    • BILLYBOSS
      • 7 privesc_2
      • 6 privesc_1
      • 5 box enum
      • 4 :8081
      • 3 :80
      • 2 :21 ftp
      • 1 recon
    • BOTTLENECK
      • 7 privesc > root
      • 6 www-data > bytevsbyte
      • 5 box enum PEAS
      • 4 box enum
      • 3 :80 exploit
      • 2 :80 bottleneck
      • 1 recon
    • BRATARINA
      • 4 :25 opensmtpd 6.6.2
      • 3 :80
      • 2 :139 :445 smb
      • 1 recon
    • CLAMAV
      • 4 :25 sendmail
      • 3 :80
      • 2 :139 :445 smb
      • 1 recon
    • CLYDE
      • 7 post enum
      • 6 box enum rabbitmq > privesc > root
      • 5 :4369 epmd
      • 4 :15672 rabbitmq
      • 3 :80
      • 2 :21 ftp
      • 1 recon
    • DAWN
      • 5 privesc
      • 4 box enum dawn
      • 3 cron exploit using smb
      • 2 :80
      • 1 recon
    • DIBBLE
      • 9 post enum
      • 8 box enum benjamin > privesc > root
      • 7 :3000 nodejs exploit
      • 6 :27017 mongodb
      • 5 :3000 node.js
      • 4 :80 drupal explore
      • 3 :80 drupal enum
      • 2 :21 ftp
      • 1 recon
    • FAIL
      • 5 post enum
      • 4 privesc fail2ban
      • 3 box enum fox
      • 2 :873 rsync
      • 1 recon
    • FUNBOXEASY
      • 4 post enum
      • 3 :22 ssh tony > root
      • 2 :80
      • 1 recon
    • FUNBOXEASYENUM
      • 4 privesc
      • 3 box enum www-data > privesc > root
      • 2 :80
      • 1 recon
    • G00G
      • 5 post enum
      • 4 privesc > root
      • 3 box enum fox
      • 2 :80
      • 1 recon
    • GAARA
      • 4 post enum
      • 3 gaara > root
      • 2 :80
      • 1 recon
    • HAWAT
      • 8 post enum
      • 6 :50080 nextcloud enum
      • 5 :50080 davtest
      • 4 :50080 nextcloud
      • 3 :30455 w3.css
      • 2 :17445 issue tracker
      • 1 recon
    • HELPDESK
      • 2 :8080 ManageEngine ServiceDesk Plus 7.6.0
      • 1 recon
    • HETEMIT
      • 10 post enum
      • 9 privesc > root
      • 8 box enum cmeeks
      • 7 :50000_2
      • 6 :50000_1
      • 5 :18000
      • 4 :80
      • 3 :139 :445 smb
      • 2 :21 ftp
      • 1 recon
    • HUNIT
      • 6 post enum
      • 5 privesc git-user git-repo > root
      • 4 fail privesc dademola-user git-repo
      • 3 box enum dademola
      • 2 :8080
      • 1 recon
    • HUTCH
      • 10 privesc_3 ldapsearch
      • 9 privesc_2 SharpLAPS
      • 8 privesc_1 PrintSpoofer
      • 7 box enum iis apppool
      • 6 :80 webdav
      • 5 :139 :445 smb
      • 4 ldap_2
      • 3 ldap_1
      • 2 :80 IIS 10.0
      • 1 recon
    • INTERNAL
      • 3 ms17-010
      • 2 :139 :445 smb
      • 1 recon
    • INTERFACE
      • 3 post enum
      • 2 :80
      • 1 recon
    • JACKO
      • 8 post enum
      • 7 privesc_2 PrintSpoofer
      • 6 privesc_1 PaperStream IP (TWAIN)
      • 5 box enum tony
      • 4 H2 JNIScriptEngine exploit > tony
      • 3 :8082
      • 2 :80
      • 1 recon
    • KEVIN
      • 3 :80 HP Power Manager 4.2
      • 2 :139 :445 smb
      • 1 recon
    • LAMPIAO
      • 7 post enum
      • 6 privesc KE
      • 5 box enum www-data
      • 4 drupalgeddon2 > www-data
      • 3 :1898 drupal 7
      • 2 :80
      • 1 recon
    • LOLY
      • 6 post enum
      • 5 privesc KE
      • 4 box enum www-data
      • 3 :80 wpscan
      • 2 :80
      • 1 recon
    • MEATHEAD
      • 7 privesc_2 Plantronics Hub 3.13.2
      • 6 privesc_1 PrintSpoofer
      • 5 box enum nt service\mssql$sqlexpress
      • 4 :1435 ms-sql 2017
      • 3 :1221 ftp
      • 2 :80 IIS 10.0
      • 1 recon
    • MEDJED
      • 8 privesc
      • 7 box enum
      • 6 :45332 :45443 QuizApp
      • 5 :44330 Barracuda Web-File-Server
      • 4 :44330 BarracudaDrive 6.5
      • 3 :33033
      • 2 :30021 ftp
      • 1 recon
    • METALLUS
      • 2 :40443 Application Manager
      • 1 recon
    • MONITORING
      • 4 privesc
      • 3 :80 box enum > www-data
      • 2 :80 nagios xi
      • 1 recon
    • MUDDY
      • 8 post enum
      • 7 privesc cronjob
      • 6 box enum www-data
      • 5 :80 webdav
      • 4 :8888 ladon framework
      • 3 :80 wpscan
      • 2 :80 muddy.ugc
      • 1 recon
    • MY-CMSMS
      • 6 privesc armour > root
      • 5 box enum www-data
      • 4 :80 cms ms login
      • 3 :3306 mysql
      • 2 :80 cms made simple
      • 1 recon
    • NAPPA
      • 7 post enum
      • 6 privesc
      • 5 box enum kathleen
      • 4 :8080
      • 3 :28080
      • 2 :21 ftp
      • 1 recon
    • NIBBLES
      • 5 post enum
      • 4 box enum > privesc > root
      • 3 :5437 postgresql
      • 2 :80
      • 1 recon
    • NICKEL
      • 6 :21 ftp > root
      • 5 box enum
      • 4 ssh ariah
      • 3 :8089 :33333 curl
      • 2 :8089 DevOps dashboard
      • 1 recon
    • NUKEM
      • 6 post enum
      • 5 privesc dosbox
      • 4 box enum http > commander
      • 3 :80 wordpress + exploit
      • 2 :80
      • 1 recon
    • PAYDAY
      • 6 patrick > privesc > root
      • 5 box enum_2
      • 4 box enum www-data
      • 3 :80 cs-cart internetshop
      • 2 :139 :445 smb
      • 1 recon
    • PEBBLES
      • 3 zoneminder sqlmap
      • 2 http
      • 1 recon
    • PELICAN
      • 7 post enum
      • 6 privesc > root
      • 5 box enum charles
      • 4 :8080 :8081
      • 3 :631 cups 2.2
      • 2 :139 :445 smb
      • 1 recon
    • PEPPO
      • 9 post enum
      • 8 privesc docker socket > root
      • 7 box enum eleanor
      • 6 :22 ssh eleanor
      • 5 docker enum postgres
      • 4 :5432 postgres
      • 3 :8080
      • 2 :113 ident
      • 1 recon
    • PHOTOGRAPHER
      • 6 post enum
      • 5 box enum > privesc
      • 4 :8000 koken cms
      • 3 :80
      • 2 :139 :445 smb
      • 1 recon
    • POSTFISH
      • 10 post enum
      • 9 privesc > root
      • 8 exploit /etc/postfix/disclaimer
      • 7 box enum
      • 6 :22 ssh
      • 5 sending mail to phish
      • 4 :110 pop3
      • 3 :25 smtp
      • 2 :80
      • 1 recon
    • POTATO
      • 6 post enum
      • 5 :22 ssh, box enum
      • 4 :80 strcmp php
      • 3 :80
      • 2 :2112 ftp
      • 1 recon
    • QUARTERJACK
      • 8 post enum
      • 7 privesc > root
      • 6 box enum apache
      • 5 :8081 rconfig
      • 4 :80
      • 3 :139 :445 smb
      • 2 :21 ftp
      • 1 recon
    • SEPPUKU
      • 10 privesc
      • 9 ssh tanto > privesc > root
      • 8 box enum samurai
      • 7 box enum seppuku
      • 6 :7601
      • 5 :7080
      • 4 :8088
      • 3 :80
      • 2 :139 :445 smb
      • 1 recon
    • SHENZI
      • 7 post enum
      • 6 privesc .msi
      • 5 box enum
      • 4 :80 wordpress > shenzi
      • 3 :80 xampp
      • 2 :139 :445 smb
      • 1 recon
    • SIROL
      • 5 post enum
      • 4 docker breakout > root
      • 3 :5601 kibana 6.5.0
      • 2 :80 php calculator
      • 1 recon
    • SLORT
      • 6 privesc
      • 5 box enum
      • 4 :4443 xampp
      • 3 :8080 xampp
      • 2 :21 ftp
      • 1 recon
    • SNOOKUMS
      • 8 post enum
      • 7 privesc
      • 6 box enum michael
      • 5 box enum apache
      • 4 :80
      • 3 :139 :445 smb
      • 2 :21 ftp
      • 1 recon
    • SORCERER
      • 7 post enum
      • 6 privesc > root
      • 5 box enum max
      • 4 :7742
      • 3 :8080 tomcat 7
      • 2 :80
      • 1 recon
    • SOSIMPLE
      • 6 ssh max > steven > root
      • 5 box enum_2
      • 4 box enum_1 www-data
      • 3 :80 wordpress
      • 2 :80
      • 1 recon
    • SUNSETMIDNIGHT
      • 7 privesc
      • 6 box enum www-data
      • 5 :80 wordpress admin
      • 4 :80 simply poll plugin sqli
      • 3 :80 wordpress
      • 2 :80
      • 1 recon
      • 0 /etc/hosts
    • SYBARIS
      • 7 post enum
      • 6 privesc cron
      • 5 box enum pablo
      • 4 :6379 redis
      • 3 :80 sybaris
      • 2 :21 ftp
      • 1 recon
    • TRE
      • 5 :22 ssh > privesc > root
      • 4 box enum www-data
      • 3 :80 mantis bug tracker
      • 2 :80
      • 1 recon
    • TWIGGY
      • 5 post enum
      • 4 :4506 SaltStack 3000.1
      • 3 :8000
      • 2 :80 mezzanine
      • 1 recon
    • UC404
      • 5 post enum
      • 4 box enum brian > privesc > root
      • 3 box enum www-data
      • 2 :80 adminlte
      • 1 recon
    • UT99
      • 8 privesc_3 wlbsctrl.dll hijack
      • 7 fail privesc_2 InspIRCd
      • 6 privesc_1 FoxitCloudUpdateService
      • 5 box enum daisy
      • 4 :7778 unreal tournament
      • 3 :6667 irc via pidgin
      • 2: 80
      • 1 recon
    • WALLA
      • 7 post enum
      • 6 privesc
      • 5 box enum www-data
      • 4 :8901 lighttpd 1.4.53 > raspAP
      • 3 :25 smtp
      • 2 :23 telnet
      • 1 recon
    • WEBCAL
      • 6 privesc KE
      • 5 box enum www-data
      • 4 :53 dns
      • 3 :80 webcalendar 1.2.3
      • 2 :21 ftp
      • 1 recon
    • WOMBO
      • 6 post enum
      • 5 :6379 redis
      • 4 :27017 mongo
      • 3 :8080 nodebb
      • 2 :80
      • 1 recon
    • XPOSEDAPI
      • 3 box enum clumsyadmin > root
      • 2 :13337 remote software management api
      • 1 recon
    • Y0USEF
      • 5 post enum
      • 4 privesc
      • 3 box enum
      • 2 :80
      • 1 recon
    • ZENPHOTO
      • 9 post enum
      • 8 privesc_2 full-nelson
      • 7 privesc_1 rds
      • 6 privesc check
      • 5 box enum www-data
      • 4 :80 zenphoto 1.4.1.4
      • 3 :80
      • 2 :23 cups 1.4
      • 1 recon
    • ZINO
      • 6 post enum
      • 5 privesc > root
      • 4 box enum www-data
      • 3 :8003
      • 2 :139 :445 smb
      • 1 recon
Powered by GitBook
On this page
  1. PG boxes
  2. UT99

5 box enum daisy

PowerUp.ps1

$ powershell.exe -exec bypass -Command "& {Import-Module .\PowerUp.ps1; Invoke-AllChecks}"
[*] Checking for unquoted service paths...
ServiceName   : FoxitCloudUpdateService
Path          : C:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\
                FCUpdateService.exe
StartName     : LocalSystem
AbuseFunction : Write-ServiceBinary -ServiceName 'FoxitCloudUpdateService' -Pat
                h <HijackPath>

ServiceName   : InspIRCd
Path          : C:\Program Files (x86)\InspIRCd\inspircd.exe
StartName     : NT AUTHORITY\NetworkService
AbuseFunction : Write-ServiceBinary -ServiceName 'InspIRCd' -Path <HijackPath>

[*] Checking %PATH% for potentially hijackable .dll locations...
HijackablePath : C:\Python\Scripts\
AbuseFunction  : Write-HijackDll -OutputFile 'C:\Python\Scripts\\wlbsctrl.dll'
                 -Command '...'

HijackablePath : C:\Python\
AbuseFunction  : Write-HijackDll -OutputFile 'C:\Python\\wlbsctrl.dll' -Command
                  '...'
				  

# there is a sqlite file in C:\Users\daisy
c:\Users\daisy>dir
Directory of c:\Users\daisy
[truncated]
08/12/2020  01:04 PM            79,872 murmur.sqlite

# using sqlitebrowser on kali to open it
# table: config
certificate
-----BEGIN CERTIFICATE-----
MIIDSzCCAjOgAwIBAgIBATANBgkqhkiG9w0BAQUFADAuMSwwKgYDVQQDDCNNdXJt
dXIgQXV0b2dlbmVyYXRlZCBDZXJ0aWZpY2F0ZSB2MjAeFw0xNTEwMDEwNjIwMDla
Fw0zNTA5MjYwNjIwMDlaMC4xLDAqBgNVBAMMI011cm11ciBBdXRvZ2VuZXJhdGVk
IENlcnRpZmljYXRlIHYyMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA
rbPDJ6ilKF4Uhrc0mJJQCkC6q3y3wZ65XUbTZwt5c1CbOUvWpJ8c6eOvwJxMrvfY
QnoQYKQpsrMj/pO/SxMCDrbnSX2nZsETligsQNImGUCGLbfl7Ij/V53AkcwFDbqt
XlPNjRdK1nAEJM+kgf2fM4copTQWCxvHXVdPO7V7hbi5KMFW0yX3XIOte2z0ouD9
AYDm7UBNvyCqMli/c31FVPHJKkfQ2Zozeg3W3wuXJpz1ap3E7JuK3lp/Rl4200EF
SEx9EHsI4dTWZPjTuaXQl+BkpDxKLr0aD0Oyu5Y8FeUMsPUNeMPbiFikfMQycdE7
DohiZF/O5rz+wEWAmOybHQIDAQABo3QwcjAMBgNVHRMBAf8EAjAAMB0GA1UdJQQW
MBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQUCcyqPXe1TKG7CdRN8Nph
soxZzXowJAYJYIZIAYb4QgENBBcWFUdlbmVyYXRlZCBmcm9tIG11cm11cjANBgkq
hkiG9w0BAQUFAAOCAQEAUDCAnQU8nCsNw0KtblKeURGskqoxacCr66UKroTCFzDT
BIFaTGfAMZL7zRFUpxRiiw8zjcHZYEI0aZBVi0swtU8G/UcfO+txj5olHeU+jeKv
+X2/gR3yK1mFsmJAoAWq8w503hu9e76LZjrQgTj/JWsy6De/KyJRonDMODyFguSS
E/URm2XiS8VXjbQ/K6lu8UEGbFgRwiL3McEAznG9my4KI41Ihop0onMnhU+hk75Q
bO+0KayksuKApEeX8DN8NzHxK5YRwUtRRq0AoNw3FiSyAA5wJFHgs2BouBKMtUwl
boviAJtPquPlUoAaYZG+pnzeF7Kgitoa0z+71fBsXA==
-----END CERTIFICATE-----

key
-----BEGIN RSA PRIVATE KEY-----
MIIEowIBAAKCAQEArbPDJ6ilKF4Uhrc0mJJQCkC6q3y3wZ65XUbTZwt5c1CbOUvW
pJ8c6eOvwJxMrvfYQnoQYKQpsrMj/pO/SxMCDrbnSX2nZsETligsQNImGUCGLbfl
7Ij/V53AkcwFDbqtXlPNjRdK1nAEJM+kgf2fM4copTQWCxvHXVdPO7V7hbi5KMFW
0yX3XIOte2z0ouD9AYDm7UBNvyCqMli/c31FVPHJKkfQ2Zozeg3W3wuXJpz1ap3E
7JuK3lp/Rl4200EFSEx9EHsI4dTWZPjTuaXQl+BkpDxKLr0aD0Oyu5Y8FeUMsPUN
eMPbiFikfMQycdE7DohiZF/O5rz+wEWAmOybHQIDAQABAoIBAQCeTOsXo3wQk9zF
AQWv3fePwHneeuTEUbDAryFOEYj3bIhp6RGOKWuiQ9wR/t9rvXea7b8rM7DEqLmu
8lstQf9oBYw2z4rV/DOrbqUV1e7eqI0f8S5bKGb8JEoxFOuuHWiORHVZldagIqnE
Gm/j/40s2opSNGu6Z/CCwmT1F2mg7Lz7xKItyX5R18cSj0saJuiOz5NotRqKmkBv
HE6YtZ6aXaqZd1zz5T/rXTXNfCVCvCW1/SdTW+Jw25z6Q3HMqmx6TXBzogCyMjug
hpjoS2J87qtSVdmYZWc4r9HT9Z8u3WMVmn0qvLbQSRzwNt1zTWslpvo8+P4RZ4r2
DSDuoaDBAoGBAN5a3gL7fJh4sHINoTpOKX3FfKIEOEzoVW1C0dYYfTWfIuO/0d8d
v0VdQLf/NogJS6P/swUr3shhbyb9S0uuvtwjcD2xtcvLBZcUI76CESdNKuJTbEn8
2C81EXh6CbZA01nhCCxymezQ5t67//V84WT9Cv7XXUQhgkW+vxt3FjPJAoGBAMf8
SK4gQTkfV+vxgqqCLTYWL4z6WHEskRYhecVsgRsaY1DiWwiQxN+5qgurRBqQRvO2
Fdq6cKDdDzit4mx5pAr3Ori8Gw5rbuBSImi59VRudbqL/eyAuyU0byrInomIlUCC
1bZ9oWIkCEhouC2V6m8BX30QD4z2mZe/GLBUvQ61AoGAWxjbUFl8SHNZxsByx5Jy
SUb5st8LueaN6T+w/If39FoIT0qtTz2+uUplU3zJ+J3mUYBW9c1tbqcMhOrNSGqF
Y2dZes0t8BpzZdwocMqVAIcLBMKs4PsoDt8tEzDcfcC9Vlttn9gr2+wSSjq3uPm6
1kcdlB7j5R/dYXmujjAR9pECgYBx78AQxHukacETwaLqNgRAHl+0+CRPRk7axvOz
kN/1axFOUcf/l0szE3pX75l7cNubmg/VcAce/xLe/eJUXvEg9j3UZgccLgUbdG/6
LoghNFWKlJt0lNsKlVcIjwgT32b5PBE6SVUaruCxMEhOYG0SFTwr6myRqSVUmSEd
xQl5SQKBgFxIglRfwMQl1otJ/b4zOCcScq2HEMrOLpawTYO3z8OZrIx9Ylh/+76r
rm6HGeSBdSpjDXtV51eKvAz+vBgXKP+GYRccQBWU9LpVyAXRo24LWGv2drN3/bWg
y16dsbF5QWKd+efEXmnXzlGAbN+aH2Wc3b8VAdh70UsbMBQwIeV0
-----END RSA PRIVATE KEY-----

# table: user_info
user_id | value
2 | d5d9bba5a4a6bd45c28e825a2954b97bfc56969e
1 | ef120c98664439173d6a4545d264d506183775de

# table: users
name | pw
SuperUser | c01ddbea603260933ca25bda4a67079216947ed6

# cracked hash
c01ddbea603260933ca25bda4a67079216947ed6:sha1:cooows
# tried PsExec - bad password for all users
Previous6 privesc_1 FoxitCloudUpdateServiceNext4 :7778 unreal tournament

Last updated 3 years ago