type
status
date
slug
summary
tags
category
icon
password
Catagory
Materials
Retired
Retired
Due date
Jan 16, 2024 05:34 AM
Status
Belong in

Progress

notion image
notion image
Using to find the hidden directory.
notion image
notion image
notion image
遠端登入該windows主機
notion image
找到flag1
notion image
Using 弱點,此弱點利用 Windows Certificate Dialog繞過 UAC(User Account Control)機制,並取得NT AUTHORITY\SYSTEM
notion image
 
notion image
notion image
notion image
notion image
找出flag2的位置
 
notion image
使用 ,使用exploit/multi/script/web_delivery,產生reverse shell payload及server
notion image
notion image
💡
檢查攻擊機PORT有沒有被占用
notion image
可以透過下列的方式傳送payload到victim
【方法一】
notion image
notion image
執行payload
執行payload
得到reverseshell
得到reverseshell
notion image
【方法二】
在victim上直接連metasploit上架的server
notion image
notion image
 
 

Reference

Tryhackme - Mr Robot從零開始PWN