> For the complete documentation index, see [llms.txt](https://writeups.adityadindi.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://writeups.adityadindi.com/tryhackme/walkthroughs-easy/blaster.md).

# Blaster

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-MeW8nQUslW16tdIYWop%2F-MeW8yOA4wzQs3kZDBR1%2Fimage.png?alt=media\&token=bf8af8b0-60ec-4c79-900c-539db560dbd0)

## Activate Forward Scanners and Launch Proton Torpedoes

Lets run nmap scans to find open ports and the services running on them

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-MeW91B6nNOiiptl8y--%2F-MeWDEVFHTquifjXfDgR%2Fimage.png?alt=media\&token=3bd3e0b7-d265-474c-ac6e-336db9de6143)

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-MeW91B6nNOiiptl8y--%2F-MeWFzQyzItLSIAR5X7q%2Fimage.png?alt=media\&token=c2dcef09-69dd-4292-9cd1-da3cc5f0e4de)

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-MeW91B6nNOiiptl8y--%2F-MeWDH2rtOTRcZTtFif1%2Fimage.png?alt=media\&token=8f5458b6-dc12-4287-9d7b-4c5999f710ab)

Lets check the website

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-MeW91B6nNOiiptl8y--%2F-MeWDOibfiZ9VTSuhZIp%2Fimage.png?alt=media\&token=b2f15ed9-b385-431f-8c71-359cb17991ea)

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-MeW91B6nNOiiptl8y--%2F-MeWDizzo9GGhBqbTkDQ%2Fimage.png?alt=media\&token=42f616c8-7464-4380-bf1b-068875fb4b78)

Looks like there is nothing interesting here, lets look for hidden directories and pages with gobuster

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-MeW91B6nNOiiptl8y--%2F-MeWEoxABma4vVwnUAww%2Fimage.png?alt=media\&token=580d65ad-b823-4113-998d-f935ef6dc79d)

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-MeW91B6nNOiiptl8y--%2F-MeWErn9JzheZ94uuQ0F%2Fimage.png?alt=media\&token=22973ad0-dc92-4c6d-ae36-03acee109078)

Lets look at this directory

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-MeW91B6nNOiiptl8y--%2F-MeWEz2bI4WiWJioJeji%2Fimage.png?alt=media\&token=a4f524e5-8eac-4e63-ab28-33c3a9494c8b)

We have a possible username Wade.

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-MeW91B6nNOiiptl8y--%2F-MeWF3s3d4biW0HA9fzQ%2Fimage.png?alt=media\&token=9ed5438d-eef6-4bb6-9359-5893b39e5bca)

Lets look at the website and see if we can find anything interesting. Looking around we come around this post

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-MeW91B6nNOiiptl8y--%2F-MeWGLiNbAClqMm6an--%2Fimage.png?alt=media\&token=44127109-4353-4bb4-b060-9a3282128c52)

After we click on it, we get to this page

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-MeW91B6nNOiiptl8y--%2F-MeWGTaBbIUpNbeuDpwZ%2Fimage.png?alt=media\&token=0ec5b69f-b008-4e53-8d80-58a94b9339f0)

It looks like a password

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-MeW91B6nNOiiptl8y--%2F-MeWGY4_LH9O2tA4sUCC%2Fimage.png?alt=media\&token=16849bf8-5169-475b-8f7f-760b55a7d76c)

Now lets try to login through Remote Desktop with the credentials we have. We can use remmina to do this.

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-MeW91B6nNOiiptl8y--%2F-MeWGsHEWpOREcm5kCmU%2Fimage.png?alt=media\&token=d39f54c8-4894-45ef-a89b-e6c20f88d5dc)

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-MeW91B6nNOiiptl8y--%2F-MeWGyWsf7uQiyCfyM29%2Fimage.png?alt=media\&token=5efe7ca0-d602-4473-a630-3421dffe2823)

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-MeW91B6nNOiiptl8y--%2F-MeWH3ladaFHd9zYv4fc%2Fimage.png?alt=media\&token=0f540f23-a5d9-432c-bfdb-86f978c9978e)

We are logged in, lets read the user.txt file

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-MeW91B6nNOiiptl8y--%2F-MeWHEutLYJ3AdRYnXaL%2Fimage.png?alt=media\&token=5907b8a0-83d5-48af-9051-e477d6b11454)

## Breaching the Control Room

Lets look for interesting information like what the user what looking at, lets go to Internet Explorer ;-; and look at the history.

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-MeW91B6nNOiiptl8y--%2F-MeWJ-kNN_t6o53dMaD0%2Fimage.png?alt=media\&token=6761747c-47ed-423d-84fd-648c843477f7)

We have the CVE number

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-MeW91B6nNOiiptl8y--%2F-MeWJBrtOysWGlKTNwoH%2Fimage.png?alt=media\&token=c1afff5a-69ca-4499-8552-18785b7d5739)

We need an executable that is necessary for the exploitation of this vulnerability, and we can find this on the desktop

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-MeW91B6nNOiiptl8y--%2F-MeWJwJrNlb7dOPvnDyo%2Fimage.png?alt=media\&token=9cc25d6b-678c-447c-8767-868c5161659f)

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-MeW91B6nNOiiptl8y--%2F-MeWK-D0_oCYVSSHJsQH%2Fimage.png?alt=media\&token=9502ffb1-9b2f-4416-a863-3f7e2c0d94fb)

Lets look at this vulnerability closer and use it to get a shell on the machine

First lets look at this executable by clicking it.

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-MeW91B6nNOiiptl8y--%2F-MeWKMOUyv83w2ZJr2EI%2Fimage.png?alt=media\&token=eeccd09d-6621-4ec9-9d41-5dcd2325c1b7)

Lets go to show more details > Show information about the publisher's certificate

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-MeW91B6nNOiiptl8y--%2F-MeWK_jJ0NIl_uxpmuAy%2Fimage.png?alt=media\&token=d2193193-6008-478e-abf8-713b07c78311)

Lets click issued by link, and close the tabs, now lets go to internet explorer and hit Ctrl + s

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-MeW91B6nNOiiptl8y--%2F-MeWLyHIvO1cw0xHpIB3%2Fimage.png?alt=media\&token=75a9ee76-eae6-4f2e-9294-7073acb54d64)

We have an error, now lets click ok and we see that the file explorer is open, lets open cmd

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-MeW91B6nNOiiptl8y--%2F-MeWMC4Dr4J4JmjuIxjT%2Fimage.png?alt=media\&token=d5e76863-9fce-42d7-97bc-a69f4607e549)

Now lets check who we are on the system

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-MeW91B6nNOiiptl8y--%2F-MeWMI_JBJDUN-aKy3rN%2Fimage.png?alt=media\&token=7ee47b9b-8d6b-4db7-97d2-113065883179)

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-MeW91B6nNOiiptl8y--%2F-MeWMPDQpBCBuakblNle%2Fimage.png?alt=media\&token=5f987a5e-daca-45b2-8176-c5f1ef91eb2a)

Lets read the root flag

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-MeW91B6nNOiiptl8y--%2F-MeWMh9JifcYzj9z8bW2%2Fimage.png?alt=media\&token=b1622a1a-f69d-488e-8469-14ffc009abdc)

## Adoption into the Collective

Lets follow the steps mentioned in the room

First lets go to our machine and launch metasploit and select the module they provided

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-MeW91B6nNOiiptl8y--%2F-MeWNRCNdPusnv8K7hIE%2Fimage.png?alt=media\&token=e58d6d63-4883-41e4-b7a8-b19876d9ab11)

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-MeW91B6nNOiiptl8y--%2F-MeWNZYkCSw4tn3q9aeU%2Fimage.png?alt=media\&token=a4ea3a43-fd95-4cb1-805d-d57fd9067f34)

Now lets set the target to PSH

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-MeW91B6nNOiiptl8y--%2F-MeWNjMvFUPv3rV88Y2V%2Fimage.png?alt=media\&token=3de00d02-d295-4850-b789-14540bb7897c)

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-MeW91B6nNOiiptl8y--%2F-MeWNmGkuJiyUpcS30o4%2Fimage.png?alt=media\&token=598f2e4c-e236-4d53-b3b3-48f0a972c75c)

Lets set the options

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-MeW91B6nNOiiptl8y--%2F-MeWO4Y6nmbCJ9smn4s7%2Fimage.png?alt=media\&token=9fc3e44a-c0fd-41df-84ae-6a6dfa7d2a06)

Lets set the payload the run the exploit as a job

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-MeW91B6nNOiiptl8y--%2F-MeWPW9RD3rh1J7xG-qp%2Fimage.png?alt=media\&token=7d0928f6-f12f-472e-8eaa-77681fe42e4e)

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-MeW91B6nNOiiptl8y--%2F-MeWPSkpiYqpcsFgoXwV%2Fimage.png?alt=media\&token=cdf433f7-287a-4f13-8f15-62c7532a8aad)

Lets select the command and paste it in the terminal of the machine we just exploited

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-MeW91B6nNOiiptl8y--%2F-MeWPf4ZkP-aZMXbfbhO%2Fimage.png?alt=media\&token=7257ae74-249a-4dec-8f98-1ef13ce55320)

And we should get a meterpreter shell

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-MeW91B6nNOiiptl8y--%2F-MeWQG9RBnqqtc_NmM1w%2Fimage.png?alt=media\&token=45808917-a35b-4b4e-bd40-331981771ac3)

We can get persistence with this command

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-MeW91B6nNOiiptl8y--%2F-MeWQVQfVHVtY_L9SWVc%2Fimage.png?alt=media\&token=e0b24236-4586-4cb7-8ad3-737c56cbd7ed)
