Hack The Box

Hack The Box: Grandpa Walkthrough

Grandpa exploits an IIS 6 WebDAV buffer overflow and a Windows privilege-escalation flaw to reach SYSTEM.

Grandpa Hack The Box machine artwork
Official Hack The Box machine artwork for Grandpa.Hack The Box machine page opens in a new tab

Recon & Enumeration

Use nmap to scan for open ports and services:

HackTheBox “Grandpa” Walkthrough, figure 2

Visit the site.

HackTheBox “Grandpa” Walkthrough, figure 3

Hop into searchsploit to look for exploits affecting IIS 6.0 WebDAV.

HackTheBox “Grandpa” Walkthrough, figure 4

We will conduct a Google search to explore alternative versions of the first exploit in the results of searchsploit as it failed to work with me here.

HackTheBox “Grandpa” Walkthrough, figure 5

We will go with the Python script here opens in a new tab and have a look at it to gain insights into the prerequisites for this exploit.

HackTheBox “Grandpa” Walkthrough, figure 6

Download it to our attack box.

HackTheBox “Grandpa” Walkthrough, figure 7

Add the shebang line to the location of our python interpreter.

HackTheBox “Grandpa” Walkthrough, figure 8

Launch our listener.

HackTheBox “Grandpa” Walkthrough, figure 9

Launching the exploit.

HackTheBox “Grandpa” Walkthrough, figure 10

And we have a shell.

HackTheBox “Grandpa” Walkthrough, figure 11

We are going to need to escalate our privileges here as we have limited access rights, we can check which privileges have been assigned to this account.

HackTheBox “Grandpa” Walkthrough, figure 12

Also have a look at the system's information.

HackTheBox “Grandpa” Walkthrough, figure 13

Having SEImpersonalPrivilege enabled on the target machine and running Windows 2003 with IIS 6.0, means that we are lucky to use Token Kidnapping exploit opens in a new tab and have a system shell.

Download the binary file of the exploit here opens in a new tab to our attack box.

HackTheBox “Grandpa” Walkthrough, figure 14

We will create a "temp" directory within the C partition of the target machine.

HackTheBox “Grandpa” Walkthrough, figure 15

As "certutil.exe" failed to download the exploit via an HTTP server, we will deploy an SMB server from our attack box's working directory to transfer "Netcat" and "Churrasco.exe".

HackTheBox “Grandpa” Walkthrough, figure 16

Copy "Netcat" and "Churrasco.exe".

HackTheBox “Grandpa” Walkthrough, figure 17

Launch a listener on our attack box.

HackTheBox “Grandpa” Walkthrough, figure 18

Proceed with executing the command below to establish a connection back to our attack box using "Netcat".

HackTheBox “Grandpa” Walkthrough, figure 19

And we get a system shell on our listener.

HackTheBox “Grandpa” Walkthrough, figure 20

Further reading

Evidence connected to this article.

Back to article start