Craft2
Gaining Access
$ nmap -p- --min-rate 4000 192.168.197.188
Starting Nmap 7.93 ( https://nmap.org ) at 2023-07-05 23:51 +08
Nmap scan report for 192.168.197.188
Host is up (0.17s latency).
Not shown: 65531 filtered tcp ports (no-response)
PORT STATE SERVICE
80/tcp open http
135/tcp open msrpc
445/tcp open microsoft-ds
49666/tcp open unknownODT Macro Fail -> NTLM Steal


SMB Shares -> Upload Web Shell

Privilege Escalation
RunasCs.exe -> Lateral Movement Fail
MySQL Arbitrary Write -> WerTrigger



Last updated