Post

HackTheBox_Grandpa | w/ Metasploit

HTB - Grandpa

Overview

Nmap Scan Results

Grandpa is an easy-tier machine on Hack The Box, offering insight into basic enumeration, vulnerability exploitation, and privilege escalation using Metasploit.

Enumeration

Nmap Scan Results

To start the enumeration, I performed an Nmap scan to discover open ports and services running on the target machine.

Nmap Scan Results

Homepage

The target’s homepage reveals some basic information.

Homepage

Vulnerabilities

Port 80/tcp

The web service running on port 80 was found to be vulnerable. Here’s a link to the exploit.

Exploitation

With Metasploit

Using the vulnerability we found earlier, we gained access to the system. Now, let’s look around.

On trying to get the system information, we encounter this:

System Access

Listing Processes

Let’s list out the processes.

Privilege Check

Migrating to NT Authority

Time to migrate into one of the NT Authority services.

System Information

Exploit Suggester

Now, let’s run a local exploit suggester and look for exploits for this system.

Process List

Privilege Escalation

Let’s go with the client_copy_image exploit

Exploit Suggester

and there we go, we have escalated our privilege.

Root Flag

Exploit Suggester

User Flag

Client Copy Image

Pwned

This post is licensed under CC BY 4.0 by the author.

Comments powered by Disqus.