Craft
Last updated
Last updated
Host:
From website: admin@craft.offsec There is a file upload
We need an ODT file for exploiting
Now create an odt file Then add the macro: Tools-> macros->Organise macros-->Basic Create a macro
Then we can configure it to open on document open:
Tools-->Customise:
Now we can upload the file and get a shell:
Shell: \
Now we find the files for the web server: We can put a webshell:
and make a reverse shell:
We can use PrintSpoofer:
Now we can run it: Now we get a shell: \
Now using whoami /priv
:
We get a shell as nt authority\system: